Phishing Campaigns Exploit Passkeys to Compromise Microsoft Cloud Accounts

Microsoft has reported two significant phishing campaigns targeting cloud accounts, utilizing advanced social engineering techniques and passkey-themed tactics.

Microsoft has revealed details of two phishing campaigns that exploit passkey-themed social engineering to compromise cloud accounts and exfiltrate sensitive data. The attacks leverage third-party email delivery systems to distribute fraudulent messages, primarily targeting enterprise users in the U.S.

First Campaign: Executive Impersonation

The first campaign involved the distribution of over a million scam emails between August 3 and 5, 2026. Attackers impersonated CEOs of various companies, attempting to persuade accounts payable departments to initiate Automated Clearing House (ACH) transfers for fictitious ServiceNow subscriptions. This sophisticated scheme involved the use of generative artificial intelligence (AI) to create tailored email templates.

According to Microsoft, the attackers registered impersonation domains and sent payment requests that included fabricated invoices and supporting email threads to reduce skepticism among recipients. The emails contained a fake approval for the invoice, tricking targets into transferring funds to accounts controlled by the attackers.

Second Campaign: Cloud Compromise via Passkey Phishing

The second campaign focused on cloud-based intrusions, where attackers engaged in suspicious sign-ins followed by adding their own authentication methods. This activity has been detected since May 2026 and is characterized by high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and mailbox data collection.

Attackers initiated their efforts by contacting users, posing as IT help desk personnel, and urging them to update their passkeys or multi-factor authentication (MFA) settings. Unsuspecting employees were redirected to counterfeit websites that mimicked legitimate Microsoft sign-in pages, allowing attackers to capture credentials or gain unauthorized access.

Exploitation Techniques and Threat Actor Insights

Microsoft noted that the attackers invested significant effort in pre-attack research, gathering information about employees and organizational structures from public sources. Some actors also exploited already compromised accounts to expand their reach through similar phishing messages sent via Microsoft Teams.

The threat actors have been linked to a cybercrime collective known as UNC6671, which operates under various aliases and shares infrastructure for phishing campaigns. Microsoft attributed initial access activities to multiple threat actors, including Storm-3121 and Storm-3032, with the latter being associated with UNC6671.

Detection Challenges and Recommendations

The attacks highlight a critical detection challenge, as Microsoft Graph abuse may not appear suspicious when viewed through isolated API calls. Microsoft emphasized the importance of assessing Graph activity holistically, focusing on behavioral patterns and cross-event correlations rather than individual requests.

While the exact connections between the threat actors remain unclear, the campaigns underscore the evolving nature of phishing tactics and the need for organizations to remain vigilant against such sophisticated attacks.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 392

Newsletter Updates

Enter your email address below and subscribe to our newsletter