Cybersecurity and Digital Privacy

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft’s threat intelligence division has released a comprehensive security advisory detailing two distinct, sophisticated cyberattack campaigns. These operations leverage advanced techniques, including generative artificial intelligence (AI) to execute large-scale financial fraud and targeted social engineering centered around passkeys to compromise enterprise cloud environments. The disclosures highlight the evolving tactics employed by cybercriminals to bypass multi-factor authentication (MFA) and manipulate corporate accounts payable departments through highly coordinated, multi-layered narratives.

The first campaign relies heavily on generative AI to orchestrate invoice fraud on a massive scale, specifically targeting enterprise organizations across the United States. Between August 3 and 5, 2026, threat actors deployed over one million scam emails. These messages were meticulously crafted by masquerading as chief executive officers (CEOs) and other top-tier executives of targeted companies. The primary objective of these communications was to convince accounts payable and finance personnel to initiate Automated Clearing House (ACH) transfers for purported annual subscriptions to enterprise software platforms like ServiceNow.

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Unlike conventional invoice scams—which typically depend on a single, isolated social engineering lure—this operation integrated multiple elements to build a unified narrative designed to dissolve recipient skepticism. According to the Microsoft Security Research team, the attack infrastructure involved registering custom executive impersonation domains, dispatching payment requests through trusted email delivery infrastructure, and embedding fabricated invoices alongside forged supporting conversations. By manufacturing realistic email threads and affixing accurate executive signatures gathered from professional networking and social media platforms, the operators significantly increased the perceived legitimacy of the requests.

The campaign primarily targeted enterprise users in the United States, focusing on sectors such as IT services, consumer goods, real estate, and discrete manufacturing. By utilizing generative AI tools, the threat actors rapidly generated custom email templates and draft messages tailored to individual recipients, maximizing operational efficiency while maintaining a high degree of personalization.

In parallel with the financial fraud campaign, Microsoft documented a separate, identity-focused threat vector active since May 2026. This second campaign centers on cloud-based intrusions that combine advanced social engineering with adversary-in-the-middle (AitM) techniques and device-code authentication flows to breach Microsoft accounts and compromise corporate identities.

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

The attack methodology typically initiates with a telephone call or direct message directed to an employee’s personal phone number. The threat actor, posing as a member of the organization’s IT help desk, creates a sense of urgency by claiming that the target must immediately update their passkey, multi-factor authentication, or single sign-on (SSO) configuration to prevent severe access disruptions. Victims are subsequently redirected via SMS messages to counterfeit websites that meticulously replicate authentic Microsoft sign-in interfaces.

Through these adversary-in-the-middle setups or device-code phishing mechanics, the attackers intercept credentials or trick unsuspecting users into authorizing access on their behalf. To heighten the plausibility of the ruse, the threat actors register specialized malicious domains incorporating the victim organization’s name as a subdomain—typically following the structural pattern of companyname.maliciousdomain.com—featuring terms related to passkeys, SSO enrollment, account activation, and identity verification.

Security researchers have identified significant operational overlaps between these cloud intrusion activities and a loose-knit cybercrime collective tracked across the cybersecurity industry under various designations, including Cordial Spider, O-UNC-045, PREY-0058, and UNC6671. This e-crime adversary is known for operating multiple public extortion brands while sharing underlying phishing infrastructure, commoditized phishing panels, and vishing callers.

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft has attributed the initial access vectors observed in these campaigns to specific threat groups within its tracking taxonomy, namely Storm-3121 and Storm-3032. While Storm-3121 has been associated with initial access operations leading to extortion brands such as ShinyHunters and Falcon (CL-CRI-1182), Storm-3032 corresponds to UNC6671—a faction that reportedly splintered from the BlackFile (CL-CRI-1116) group to operate under the Helix extortion banner.

Once initial access to a corporate environment is achieved, the threat actors systematically pivot toward establishing persistent footholds rather than relying solely on stolen credentials. Investigations reveal that attackers frequently enroll an additional, actor-controlled multi-factor authentication method—such as registering a new phone number, downloading a secondary authenticator application, or configuring a software-based one-time password (OTP) token.

By establishing this secondary authentication factor, the adversaries can seamlessly sign into the corporate account without requiring further interaction from the legitimate user. This persistence mechanism, combined with unrevoked sessions or valid credentials, enables prolonged operational longevity within the compromised ecosystem.

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Following successful persistence, the threat actors engage in extensive post-exploitation and reconnaissance activities. Observations from Microsoft’s telemetry indicate instances where adversaries executed anomalous sign-ins to Microsoft Office Home from unmanaged devices. This maneuver facilitated expanded access to auxiliary applications, including SharePoint Online and OneDrive, through the Microsoft Graph API, allowing the actors to enumerate sensitive internal files, inspect corporate directory services, and harvest mailbox data via REST APIs.

The abuse of the Microsoft Graph API presents a profound detection challenge for enterprise security teams. Because individual API requests often mimic standard administrative or user behaviors, malicious actions rarely trigger immediate alerts when examined in isolation. Microsoft emphasizes that defending against this class of threat requires a holistic analytical approach—prioritizing behavioral progression, cross-event correlation, and pattern recognition over static, single-event evaluations.

The convergence of AI-assisted financial fraud and sophisticated identity-based social engineering marks a critical escalation in the threat landscape. Organizations are increasingly forced to contend with adversaries who combine automated content generation with deep pre-attack reconnaissance. Cybersecurity experts recommend that enterprises reinforce employee awareness training regarding out-of-band verification procedures for financial transactions, strictly monitor Microsoft Graph API activity for anomalous patterns, and accelerate the transition toward robust, phishing-resistant authentication methods while implementing continuous behavioral monitoring across cloud and identity infrastructures.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button