Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Threat Actors Employ Sophisticated Passkey Phishing Tactics to Hijack Microsoft Cloud Accounts and Exfiltrate Sensitive Data




Threat Actors Employ Sophisticated Passkey Phishing Tactics to Hijack Microsoft Cloud Accounts and Exfiltrate Sensitive Data. A recent phishing campaign by Microsoft has uncovered a sophisticated social engineering tactic used by threat actors to breach Microsoft cloud accounts and exfiltrate sensitive data. The campaign involved sending over a million scam emails masquerading as CEOs of various target companies, aiming to persuade accounts payable departments to initiate ACH transfers. The attackers used generative AI to create email templates and draft emails tailored to their recipients, primarily targeting enterprise users in the U.S. This attack highlights the critical detection challenge of Microsoft Graph abuse and the need for holistic assessment of Graph activity.

  • Microsoft uncovered a sophisticated phishing campaign that utilized passkey-themed social engineering tactics to hijack Microsoft cloud accounts.
  • The campaign sent over a million scam emails masquerading as CEO messages to persuade accounts payable departments to initiate ACH transfers.
  • The attackers used generative AI to create tailored email templates and draft emails, primarily targeting enterprise users in the U.S.
  • The campaign followed a multi-step approach, including registering impersonation domains, sending payment requests, and attempting to convince finance personnel to initiate ACH transfers.
  • The attackers relied on bogus domains and content designed to impersonate trusted brands and individuals to lend credibility to the deception.
  • A second campaign targeted multiple accounts, using cloud-based intrusions, suspicious sign-ins, and high-volume Microsoft Graph activity.
  • The attackers used identity-focused social engineering to trick employees into updating their passkey, MFA, or SSO configuration.
  • The campaign overlaps with a known cybercrime collective, Cordial Spider, and has been attributed to multiple threat actors, including Storm-3121 and Storm-3032.



  • The threat landscape continues to evolve at an unprecedented pace, with cybersecurity experts and researchers constantly discovering new and innovative methods employed by malicious actors to breach organizational security systems. Recently, a sophisticated phishing campaign has been uncovered by Microsoft, which utilized passkey-themed social engineering tactics to hijack Microsoft cloud accounts and exfiltrate sensitive data.

    The campaign, which began in August 2026, involved the sending of over a million scam emails masquerading as chief executive officers (CEOs) of various target companies, aiming to persuade accounts payable departments at those firms to initiate Automated Clearing House (ACH) transfers for a supposed ServiceNow annual subscription. The attackers used generative artificial intelligence (AI) to create email templates and draft emails tailored to their recipients, primarily targeting enterprise users in the U.S., spanning IT services, consumer goods, real estate, and discrete manufacturing sectors.

    According to Microsoft's Security Research team, the campaign followed a multi-step approach, which included registering impersonation domains, sending executive-themed payment requests through trusted infrastructure, embedding fabricated invoices and supporting conversations, and attempting to convince finance personnel to initiate ACH transfers. The spoofed email messages contained a purported "approval" of the fake invoice to trick recipients into making payments to attacker-controlled accounts.

    To lend credibility to the deception, the attackers included a forged email thread along with the fabricated invoice, and even went so far as to identify CEOs, CFOs, and presidents at victim organizations and plug their names and email addresses into the emails' signatures. The campaign also heavily relied on bogus domains and content designed to impersonate trusted brands and individuals.

    A second campaign, documented by Redmond, revolves around cloud-based intrusions targeting multiple accounts. Suspicious sign-ins are followed by the threat actors adding their own authentication methods, as well as high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and mailbox collection through REST APIs. This activity is consistent with "automated collection from compromised cloud identities using proxy-associated infrastructure," Microsoft said.

    The attack commonly begins with identity-focused social engineering, where the threat actors call or message a user's personal phone number, claiming to be from the organization's IT help desk and urging them to immediately update their passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to avoid access disruptions. Unsuspecting employees are redirected to counterfeit websites that mimic the legitimate Microsoft sign-in experience via SMS messages sent to their personal devices.

    The end goal is to use the pretext to guide them through adversary-in-the-middle (AitM) or device-code authentication flows and take control of their Microsoft accounts either by capturing the credentials or unknowingly granting access on the actor's behalf. Microsoft noted that the actors appear to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms.

    In a smaller number of cases, actors take advantage of already compromised accounts to expand their reach by sending similar passkey-themed messages via Microsoft Teams. The threat actor has also been observed registering domains built around themes such as passkeys, SSO enrollment, account activation, and identity verification, often including the target organization's name as a subdomain in the pattern.

    It is worth noting that this modus operandi overlaps with a loose-knit cybercrime collective tracked by the cybersecurity community under the monikers Cordial Spider, O-UNC-045, PREY-0058, and UNC6671. The e-crime adversary has been described as a coordinated group of threat actors that operates multiple public extortion brands while sharing overlaps in the underlying phishing infrastructure and targeting footprint.

    Microsoft has attributed the initial access activity observed in this campaign to a range of threat actors, including Storm-3121 and Storm-3032. While Storm-3121 carries out initial access activity leading to ShinyHunters and Falcon (aka CL-CRI-1182) extortion, Storm-3032 is its designation for UNC6671, which refers to a set of actors that broke off from the BlackFile (aka CL-CRI-1116) group and now operate under the Helix extortion brand.

    The attack highlights a critical detection challenge, as Microsoft Graph abuse rarely appears suspicious when viewed through a single API call. This attack serves as a strong example of why Graph activity must be assessed holistically, with emphasis on behavioral progression and cross-event correlation rather than individual API requests in isolation.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Threat-Actors-Employ-Sophisticated-Passkey-Phishing-Tactics-to-Hijack-Microsoft-Cloud-Accounts-and-Exfiltrate-Sensitive-Data-ehn.shtml

  • https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html


  • Published: Sun Sep 13 07:43:06 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us