Microsoft has identified two sophisticated cyberattack campaigns involving generative AI-driven financial fraud and passkey-themed social engineering tactics designed to compromise enterprise cloud environments and bypass multi-factor authentication.
Key Points
- Threat actors sent over one million scam emails in August 2026, impersonating CEOs to trick finance departments into making fraudulent Automated Clearing House (ACH) transfers.
- Attackers utilized generative AI to create convincing email templates, fabricated invoices, and forged internal communication threads to reduce recipient skepticism.
- A separate campaign targeting cloud identities uses voice phishing and counterfeit websites to trick employees into updating passkeys or multi-factor authentication settings.
- Once access is gained, attackers register their own authentication methods to maintain persistent control and use the Microsoft Graph API to exfiltrate data from SharePoint and OneDrive.
- Microsoft attributes these activities to various threat actors, including groups designated as Storm-3121 and Storm-3032, which show operational overlaps with the cybercrime collective UNC6671.