Passkey-themed phishing attacks lead to Microsoft 365 data theft

Passkey-themed phishing attacks lead to Microsoft 365 data theft
Microsoft says threat actors linked to ShinyHunters, Helix, Storm-3121, and Storm-3032 are using passkey and SSO-themed social engineering to hijack Microsoft 365 accounts and steal cloud data. After compromise, they perform Microsoft Graph reconnaissance, add their own MFA methods, and exfiltrate files and email from SharePoint Online, OneDrive, and Exchange Online. #ShinyHunters #Helix #Storm3121 #Storm3032 #UNC6671 #Microsoft365 #SharePointOnline #OneDrive #ExchangeOnline

Keypoints

  • Attackers impersonate IT help desks to trick employees into updating passkeys, MFA, or SSO settings.
  • Victims are sent to phishing pages that mimic Microsoft login screens.
  • Microsoft says the campaign uses AiTM phishing and device-code authentication flows.
  • Compromised accounts are used for Microsoft Graph reconnaissance and persistence through new MFA methods.
  • Attackers exfiltrate data from SharePoint Online, OneDrive for Business, and Exchange Online over hours or days.

Read More: https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/