Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft’s Threat Intelligence center has published a comprehensive security advisory detailing two sophisticated cyberattack campaigns. These operations demonstrate a disturbing evolution in threat actor tactics, combining generative artificial intelligence to automate financial fraud with cutting-edge, passkey-themed social engineering schemes designed to bypass multi-factor authentication (MFA) and compromise enterprise cloud environments.
The first campaign highlights the alarming weaponization of generative AI in Business Email Compromise (BEC) operations. Threat actors orchestrated a massive, targeted blast of over one million scam emails between August 3 and 5, 2026. Rather than relying on generic phishing templates, the attackers meticulously impersonated chief executive officers and senior executives across multiple corporate entities.
The primary targets of this AI-assisted onslaught were accounts payable departments within enterprise organizations operating in critical U.S. sectors, including information technology services, consumer goods, real estate, and discrete manufacturing. The financial objective was singular and direct: to manipulate finance personnel into initiating Automated Clearing House (ACH) transfers for fictitious annual subscriptions to legitimate vendors, such as software and IT service provider ServiceNow.
According to Microsoft’s security analysts, the methodology went far beyond standard invoice scams. The operation integrated executive impersonation, authentic-looking vendor branding, fabricated invoices, and convincing supporting conversations into a unified narrative. By generating realistic email threads that appeared to show internal corporate approval for the payments, the attackers successfully reduced recipient skepticism and bypassed conventional mental defenses.

Furthermore, the threat actors engaged in rigorous pre-attack reconnaissance, harvesting names, titles, and email addresses of actual CEOs, CFOs, and presidents from public professional networks. They integrated these genuine identities into email signatures, pairing them with newly registered lookalike domains to establish a false sense of absolute legitimacy.
Passkey Social Engineering and Identity Cloud Compromise
While the first campaign targeted corporate treasuries, the second documented operation focused squarely on cloud identity theft and enterprise espionage. Detected as early as May 2026, this campaign utilized targeted voice phishing (vishing) and multi-channel social engineering to infiltrate Microsoft 365 cloud environments.
The mechanics of this intrusion typically begin off-platform. Threat actors reach out to employees via personal phone numbers or messaging applications, falsely claiming to represent internal IT help desks. They create an immediate sense of urgency, instructing victims to update their passkeys, single sign-on (SSO) configurations, or multi-factor authentication methods to prevent critical access disruptions.
Unsuspecting employees are then directed to sophisticated lookalike portals via SMS links. These malicious websites mimic authentic enterprise sign-in experiences, orchestrating Adversary-in-the-Middle (AitM) intercepts or device-code authentication attacks. In some instances, attackers leveraged already compromised corporate accounts to spread similar passkey-themed lures internally via Microsoft Teams, drastically expanding their lateral reach.

Once access is secured, the attackers focus on cementing their foothold. Rather than merely exploiting stolen credentials—which can be reset or expire—the threat actors register an entirely new authentication method under their direct control, such as a rogue phone number, an unauthorized authenticator application, or a software-based one-time password (OTP) token.
With persistent, independent access established, the threat actors execute automated data collection using proxy-associated infrastructure. Investigators observed high-volume Microsoft Graph API activity, unauthorized SharePoint and OneDrive file downloads, and deep mailbox collection via REST APIs. In several notable instances, attackers utilized unmanaged devices to access Microsoft Office Home environments, delicately blending their malicious data extraction with normal administrative traffic to evade detection.
Attribution and the Cybercrime Ecosystem
Microsoft has connected these identity compromise activities to a broader, highly coordinated e-crime ecosystem. The initial access vectors bear the operational hallmarks of known threat clusters, including Storm-3121 and Storm-3032.
Storm-3032 shares significant infrastructure and tactical overlaps with a loosely knit collective tracked across the cybersecurity industry under various monikers, including UNC6671, Cordial Spider, O-UNC-045, and PREY-0058. This group is widely recognized for deploying commoditized credential-harvesting panels hosted on generic root domains, appending victim-specific subdomains to execute highly personalized voice-phishing attacks.

While Storm-3121 has historically laid the groundwork for extortion syndicates such as ShinyHunters and Falcon (CL-CRI-1182), Storm-3032 represents operatives who split from the BlackFile (CL-CRI-1116) ransomware group and now align with the Helix extortion brand. Security researchers note that these shifting alliances highlight a concerning trend: cybercrime groups are increasingly sharing initial access playbooks, modular phishing frameworks, and outsourced voice-phishing operators to scale their operations efficiently.
Implications and the Evolving Detection Paradigm
The dual campaigns analyzed by Microsoft underscore a profound shift in the threat landscape. The weaponization of generative AI for BEC attacks lowers the barrier to entry for lower-tier cybercriminals while drastically increasing the psychological plausibility of fraudulent invoices. Traditional email gateways that rely solely on static keyword blocking or basic domain reputation checks struggle to catch these multi-layered, narrative-driven fraud schemes.
Simultaneously, the pivot toward passkey- and MFA-themed social engineering demonstrates that attackers are aggressively adapting to security technologies designed to phase out traditional passwords. By exploiting human psychology and manipulating device-code enrollment flows, threat actors are successfully turning enterprise security upgrades against the organizations implementing them.
Security Implications for Enterprise Defense

From an analytical standpoint, these intrusions emphasize the urgent need for holistic telemetry analysis. Microsoft’s findings highlight that unauthorized Microsoft Graph API activity rarely triggers traditional security alerts when viewed in isolation through a single API request. Because the commands mimic legitimate administrative workflows, defenders must shift away from siloed log reviews and embrace behavioral progression modeling and cross-event correlation.
In response to these emerging threats, cybersecurity experts recommend that organizations reinforce their defensive postures through several key measures:
- Enhancing email verification protocols and implementing strict financial controls that require out-of-band, multi-person verification for any high-value ACH transfers or invoice changes, regardless of apparent executive approval.
- Training employees to recognize and report help desk requests that demand immediate updates to passkeys, MFA methods, or SSO configurations, particularly when initiated via personal communication channels.
- Restricting unmanaged device access to sensitive corporate repositories, such as SharePoint and OneDrive, through robust Conditional Access policies.
- Continuously auditing registered authentication methods within enterprise identity directories to promptly detect and neutralize unauthorized MFA device additions or rogue recovery phone numbers.
As threat actors continue to refine their use of generative AI and identity manipulation, organizations must pair advanced technological safeguards with continuous workforce vigilance to secure their digital perimeters against increasingly deceptive intrusion vectors.







