Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft detailed two abuse campaigns: one used third-party email delivery systems and AI-generated impersonation lures to push fake ACH payment requests, while another used passkey-themed social engineering to compromise cloud accounts. The activity involved bogus domains, counterfeit Microsoft sign-in pages, MFA persistence, and extensive Microsoft Graph, SharePoint, OneDrive, and mailbox abuse tied to groups including Storm-3121, Storm-3032, UNC6671, Cordial Spider, O-UNC-045, PREY-0058, ShinyHunters, Falcon, and Helix. #Microsoft #Storm3121 #Storm3032 #UNC6671 #CordialSpider #Helix #ShinyHunters #Falcon

Keypoints

  • Attackers sent over a million fake CEO payment emails to trigger fraudulent ACH transfers.
  • The scam used AI-generated templates, forged invoices, and fake email threads to appear legitimate.
  • Passkey-themed social engineering lured users to counterfeit Microsoft sign-in pages.
  • Threat actors added their own MFA methods to keep persistent access to cloud accounts.
  • The intrusions involved Graph API abuse, SharePoint and OneDrive downloads, and mailbox collection.

Read More: https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html