Microsoft Warns of Passkey Phishing Attacks Hijacking Cloud Accounts — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Microsoft disclosed that attackers sent over a million scam emails between August 3 and 5, 2026, impersonating CEOs to trick accounts payable departments into initiating ACH transfers for fake ServiceNow annual subscriptions, with generative AI used to tailor the templates.
- Microsoft documented a second campaign active since May 2026 in which threat actors contact users by phone or SMS posing as IT help desk staff, directing them to counterfeit sign-in pages that run adversary-in-the-middle or device-code phishing flows to capture credentials or grant account access.
- Threat actors registered lookalike domains including passkeyhelpdesk[.]com, secure-passkey[.]com, and setupmypasskey[.]com, embedding the target organization's name as a subdomain to lend legitimacy to the lures.
- Microsoft attributed initial access in the passkey campaign to Storm-3121 and Storm-3032; Storm-3032 is the company's designation for UNC6671, an actor group that broke from BlackFile (CL-CRI-1116) and now operates under the Helix extortion brand.
- Attackers enrolled their own MFA methods — phone numbers, authenticator apps, or OTP tokens — after initial access to maintain persistence and sign in without user participation, then used Microsoft Graph API for reconnaissance and high-volume downloads from SharePoint Online, OneDrive for Business, and Exchange Online.
- Microsoft noted that exfiltration activity lasted from several hours to multiple days, with attackers rotating infrastructure and using separate IP addresses for authentication, reconnaissance, and data theft to evade network-based detection.
Why it matters: The campaigns weaponize the very passkeys and MFA methods enterprises are rolling out to replace passwords, with attackers enrolling their own second factors to lock out legitimate users. Data exfiltration from SharePoint, OneDrive, and Exchange across multiple days means a single voice-phishing call can turn into a full cloud breach for IT, finance, and operations teams in the targeted sectors.
Ask SkimNews



