Phone numbers used to map out accounts in Microsoft Entra ID
Since 10 April 2026 a sustained, high-volume campaign has been observed against Microsoft Entra ID, using international-format phone numbers as sign-in identifiers against Microsoft's authentication services. The pattern is consistent with automated reconnaissance to identify valid phone-linked accounts and probe account recovery pathways. The use of residential proxies, VPN infrastructure and rotating browser fingerprints points to deliberate evasion of standard access controls.
What this means for your organisation
This is preparation, not the objective. The mapping sets up targeted phishing, calls to the service desk from someone impersonating an employee, or abuse of recovery features. Account recovery is often the weakest link in an otherwise tight identity platform, because it is built to help people who have lost access and therefore to lower the bar. An organisation can run disciplined MFA and still lose an account through the recovery flow.
Berigo recommends
- Review the account recovery configuration in Entra ID and switch off preview features you have no concrete need for.
- Enforce phishing-resistant MFA such as FIDO2 keys or certificate-based sign-in, and retire SMS as a second factor.
- Review sign-in logs from 10 April onwards for successful logins and token issuance you cannot account for.
- Give the service desk a fixed, documented identity verification routine before resetting MFA or passwords.
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch