Microsoft detailed two abuse campaigns: one used third-party email delivery systems and AI-generated impersonation lures to push fake ACH payment requests, while another used passkey-themed social engineering to compromise cloud accounts. The activity involved bogus domains, counterfeit Microsoft sign-in pages, MFA persistence, and extensive Microsoft Graph, SharePoint, OneDrive, and mailbox abuse tied to groups including Storm-3121, Storm-3032, UNC6671, Cordial Spider, O-UNC-045, PREY-0058, ShinyHunters, Falcon, and Helix. #Microsoft #Storm3121 #Storm3032 #UNC6671 #CordialSpider #Helix #ShinyHunters #Falcon
Keypoints
- Attackers sent over a million fake CEO payment emails to trigger fraudulent ACH transfers.
- The scam used AI-generated templates, forged invoices, and fake email threads to appear legitimate.
- Passkey-themed social engineering lured users to counterfeit Microsoft sign-in pages.
- Threat actors added their own MFA methods to keep persistent access to cloud accounts.
- The intrusions involved Graph API abuse, SharePoint and OneDrive downloads, and mailbox collection.
Read More: https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html