# Microsoft Cloud Accounts Targeted by Passkey Phishing Attacks

**Published:** 2026-09-13T12:24:21.787Z  
**Topic:** Microsoft  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/04af4551-8b55-4b03-88cf-e6b33948463e

Attackers are hijacking Microsoft 365 accounts using passkey-themed phishing. Learn how these breaches bypass MFA and what to watch for in cloud security.

Threat actors have been using passkey-themed social engineering to hijack Microsoft 365 accounts and exfiltrate data since May 2026, according to Microsoft security researchers [1]. The campaign poses a significant risk to enterprise environments, as attackers use the initial access to establish persistent control, map internal networks, and systematically download sensitive files from SharePoint and OneDrive [2].

| At a glance | |
|---|---|
| Primary Target | Microsoft 365 Cloud Accounts |
| Campaign Start | May 2026 |
| Primary Method | Passkey-themed social engineering |
| Key Impact | Persistent access and data exfiltration |

## Anatomy of the Cloud Hijack
The attack sequence typically begins with a phone call, SMS, or Microsoft Teams message from an individual posing as an IT helpdesk representative [1]. The attacker creates a sense of urgency, pressuring the employee to update their passkey, multifactor authentication (MFA), or single sign-on (SSO) settings to prevent a loss of access [2]. Victims are then directed to counterfeit sign-in pages that mimic the legitimate Microsoft experience [1].

Rather than relying solely on credential theft, the attackers often use adversary-in-the-middle (AiTM) techniques or trick the user into approving a device-code authentication request on a real Microsoft page [1]. Once inside, the threat actors move to secure a permanent foothold by registering their own MFA method—such as a new phone number or authenticator app—which allows them to bypass the victim’s security controls indefinitely [2].

## Data Exfiltration and Automation
After establishing persistence, the attackers abuse Microsoft Graph APIs to conduct reconnaissance across the victim’s environment [1]. This automated process allows them to enumerate directory users, identify privileged roles, and locate sensitive data within SharePoint, OneDrive, and Exchange Online [1]. Microsoft noted that while a single API request may appear benign, the systematic discovery and high-volume file downloads across a short period are clear indicators of a compromise [1].

The activity has been linked to various threat actors, including those tracked as Storm-3121 and Storm-3032, the latter of which is associated with the cybercrime collective known as UNC6671 [2]. These groups appear to leverage shared infrastructure and commoditized phishing panels to scale their operations, often tailoring their lures by using public professional profiling platforms to gather information on organizational structures [2].

## What to watch
*   **Expansion of Phishing Tactics:** Monitor for further use of generative AI in creating tailored, executive-themed email templates, which were recently observed in a separate million-email campaign targeting finance departments [2].
*   **API Usage Patterns:** Security teams should monitor for anomalous, high-volume Graph API requests originating from accounts that have recently registered new MFA methods [1].
*   **Infrastructure Evolution:** Watch for the registration of new domains that combine target company names as subdomains with generic "passkey" or "SSO" keywords, a hallmark of the current phishing infrastructure [2].

The shift toward passkey-themed lures highlights a move away from traditional credential harvesting toward more sophisticated methods that bypass standard MFA protections. Whether organizations can effectively counter these identity-focused attacks depends on their ability to detect the subtle transition from a single suspicious sign-in to the systematic, automated enumeration of cloud resources.

## Sources
1. Cyberpress — [Passkey Phishing Hijacks Microsoft 365 Accounts for Cloud Data...](https://cyberpress.org/passkey-phishing-hijacks-microsoft-365/)
2. Thehackernews — [Attackers Use Passkey Phishing to Hijack Microsoft Cloud...](https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html)

---
Cite as: TrendWatcher, "Microsoft Cloud Accounts Targeted by Passkey Phishing Attacks", https://www.trendwatcher.in/article/04af4551-8b55-4b03-88cf-e6b33948463e
