AUTO-UPDATED

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft has identified two sophisticated cyberattack campaigns involving generative AI-driven financial fraud and passkey-themed social engineering tactics designed to compromise enterprise cloud environments and bypass multi-factor authentication.

Key Points

  • Threat actors sent over one million scam emails in August 2026, impersonating CEOs to trick finance departments into making fraudulent Automated Clearing House (ACH) transfers.
  • Attackers utilized generative AI to create convincing email templates, fabricated invoices, and forged internal communication threads to reduce recipient skepticism.
  • A separate campaign targeting cloud identities uses voice phishing and counterfeit websites to trick employees into updating passkeys or multi-factor authentication settings.
  • Once access is gained, attackers register their own authentication methods to maintain persistent control and use the Microsoft Graph API to exfiltrate data from SharePoint and OneDrive.
  • Microsoft attributes these activities to various threat actors, including groups designated as Storm-3121 and Storm-3032, which show operational overlaps with the cybercrime collective UNC6671.

Why it Matters

These campaigns demonstrate a significant evolution in social engineering, where attackers combine AI-generated content with sophisticated infrastructure to bypass traditional security safeguards. Organizations must move beyond simple credential protection and adopt holistic behavioral monitoring to detect anomalous API activity and unauthorized authentication changes.
Internet Published by info@thehackernews.com (The Hacker News)
Read original