Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Microsoft disclosed two active campaigns: an Aug 3–5, 2026 wave of over one million scam emails impersonating CEOs to push fake ServiceNow ACH payments, and a passkey-phishing cloud intrusion operation active since May 2026.
- Threat actors in the email campaign used generative AI to tailor templates, forge approval threads, and impersonate CFOs and presidents at victim firms across U.S. IT services, consumer goods, real estate, and manufacturing, registering lookalike domains like service-nowinc[.]com.
- Attackers in the cloud campaign called victims on personal phones posing as internal IT help desks, then redirected them to counterfeit Microsoft sign-in pages to run adversary-in-the-middle or device-code phishing and capture credentials.
- The threat actors enrolled their own MFA factors—new phone numbers, authenticator apps, or OTP tokens—after initial access, letting them sign in to corporate accounts without the victim's participation and persist even after password resets.
- Post-compromise activity used Microsoft Graph API for internal reconnaissance and high-volume downloads from SharePoint Online, OneDrive for Business, and Exchange Online, with data exfiltration lasting from several hours to multiple days.
- Microsoft attributed the cloud intrusions to Storm-3121 (linked to ShinyHunters and Falcon extortion) and Storm-3032, its designation for UNC6671, which operates under the Helix extortion brand and broke off from the BlackFile group.
- Mandiant flagged that UNC6671 hosts credential harvesting panels on generic passkey-themed root domains like passkeyhelpdesk[.]com and setupmypasskey[.]com, appending victim company names as subdomains for targeted voice-phishing.
Why it matters: Passkey-themed social engineering defeats one of the strongest MFA safeguards: attackers who trick a user into approving a single sign-in can then enroll their own second factor, locking the real user out while retaining persistent access. With Graph-driven exfiltration spanning SharePoint, OneDrive, and Exchange—and activity correlating to ShinyHunters, Falcon, and Helix extortion brands—a single help-desk call can convert into multi-day data theft that looks like normal API traffic to network defenders.
Ask SkimNews



