Loading article…
Attackers are hijacking Microsoft 365 accounts using passkey-themed phishing. Learn how these breaches bypass MFA and what to watch for in cloud security.
Threat actors have been using passkey-themed social engineering to hijack Microsoft 365 accounts and exfiltrate data since May 2026, according to Microsoft security researchers [1]. The campaign poses a significant risk to enterprise environments, as attackers use the initial access to establish persistent control, map internal networks, and systematically download sensitive files from SharePoint and OneDrive [2].
| At a glance | |
|---|---|
| Primary Target | Microsoft 365 Cloud Accounts |
| Campaign Start | May 2026 |
| Primary Method | Passkey-themed social engineering |
| Key Impact | Persistent access and data exfiltration |
The attack sequence typically begins with a phone call, SMS, or Microsoft Teams message from an individual posing as an IT helpdesk representative [1]. The attacker creates a sense of urgency, pressuring the employee to update their passkey, multifactor authentication (MFA), or single sign-on (SSO) settings to prevent a loss of access [2]. Victims are then directed to counterfeit sign-in pages that mimic the legitimate Microsoft experience [1].
Rather than relying solely on credential theft, the attackers often use adversary-in-the-middle (AiTM) techniques or trick the user into approving a device-code authentication request on a real Microsoft page [1]. Once inside, the threat actors move to secure a permanent foothold by registering their own MFA method—such as a new phone number or authenticator app—which allows them to bypass the victim’s security controls indefinitely [2].
After establishing persistence, the attackers abuse Microsoft Graph APIs to conduct reconnaissance across the victim’s environment [1]. This automated process allows them to enumerate directory users, identify privileged roles, and locate sensitive data within SharePoint, OneDrive, and Exchange Online [1]. Microsoft noted that while a single API request may appear benign, the systematic discovery and high-volume file downloads across a short period are clear indicators of a compromise [1].
The activity has been linked to various threat actors, including those tracked as Storm-3121 and Storm-3032, the latter of which is associated with the cybercrime collective known as UNC6671 [2]. These groups appear to leverage shared infrastructure and commoditized phishing panels to scale their operations, often tailoring their lures by using public professional profiling platforms to gather information on organizational structures [2].
The shift toward passkey-themed lures highlights a move away from traditional credential harvesting toward more sophisticated methods that bypass standard MFA protections. Whether organizations can effectively counter these identity-focused attacks depends on their ability to detect the subtle transition from a single suspicious sign-in to the systematic, automated enumeration of cloud resources.
Coverage is mostly measured — 240 of 240 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Sep 13, 2026 · How we report
Frank Shaw is scheduled to leave Microsoft at the end of the 2026 calendar year. He has served in his current role for 17 years and has been associated with Microsoft communications for nearly 30 years.
Microsoft has disclosed two primary threats: a financial fraud campaign using generative AI to impersonate CEOs for fake invoice payments, and a cloud-based intrusion campaign using social engineering to compromise user authentication methods. These activities were documented by the Microsoft Security Research team.
Microsoft describes the financial scam as a campaign that layered executive impersonation, vendor branding, and fabricated invoices into a unified narrative to deceive finance personnel. The attackers sent over one million emails between August 3 and August 5, 2026, to solicit fraudulent Automated Clearing House transfers.
Microsoft is not naming a replacement for Frank Shaw immediately, as he remains in his position until the end of 2026. The company is currently working through next steps and expects to provide an update in the weeks following August 2026.