Skip to main content
Emerging ThreatsMalware & Ransomware

Microsoft Cloud Accounts Targeted in Passkey Phishing Campaigns

Person sits at cluttered desk, looking concerned at computer screen with phone ringing in background.

Microsoft says attackers sent “over a million scam emails between August 3 and 5, 2026,” then pivoted to passkey-themed social engineering to seize cloud accounts and siphon corporate files.

Executive impersonation and large-scale invoice fraud

Between August 3 and 5, 2026, Microsoft observed a mass email campaign that flooded enterprise inboxes with more than one million messages that impersonated company CEOs and other senior executives. The objective was straightforward: convince accounts payable teams to initiate Automated Clearing House (ACH) transfers for a fictitious ServiceNow annual subscription.

Microsoft Security Research analysts said the threat actors layered multiple social-engineering elements — executive impersonation, vendor branding, fabricated invoices, and forged email threads — into a single narrative “intended to reduce recipient skepticism.” The operators also injected names and email addresses of identified CEOs, CFOs, and presidents into message signatures to increase plausibility.

The campaign relied on bogus domains and spoofed brand content. Microsoft published examples of registered domains used to impersonate the vendor:

  • service-nowinc[.]com
  • domainlify[.]net

Microsoft also reported evidence that the operators used generative artificial intelligence to build email templates and draft tailored messages for recipients across U.S. enterprises in IT services, consumer goods, real estate, and discrete manufacturing.

Passkey-themed social engineering that begins at the personal phone

Separately, since May 2026 Microsoft has tracked cloud-targeted intrusions that begin with identity-focused social engineering. The attacker calls or messages a user’s personal phone, posing as the organization’s IT help desk and urging an immediate update to passkey, MFA, or single-sign-on settings to avoid perceived access disruptions.

Targets are redirected—typically via SMS—to counterfeit websites that mimic the Microsoft sign-in experience. The goal is to funnel users through adversary-in-the-middle (AitM) or device-code authentication flows so the attacker can either capture credentials or obtain access by tricking the victim into approving an authentication flow on the actor’s behalf.

Microsoft said attackers invested heavily in pre-attack research, likely harvesting employee and organizational information from public professional profiles. In a smaller number of cases, already-compromised accounts were used to distribute the same passkey-themed messages through Microsoft Teams.

The actors also registered a catalog of purpose-built domains that incorporate passkey and SSO themes, often appending the target organization as a subdomain. Microsoft listed multiple examples:

  • passkeyhelpdesk[.]com
  • secure-passkey[.]com
  • setupmypasskey[.]com
  • add-passkey[.]com
  • integratedsso[.]com
  • oktasession[.]com
  • syncmykey[.]com
  • portalsetuphub[.]com

From initial access to persistence: MFA enrollment, Graph API reconnaissance, and exfiltration

Once inside, actors focus on converting temporary access into persistent control by enrolling authentication methods they control — registering new phone numbers, authenticator applications, or software-based one-time password tokens. With that actor-controlled second factor, they can sign into the victim’s corporate account without further participation from the user and sustain access alongside unrevoked sessions or valid credentials.

Microsoft described a consistent post-compromise pattern: adding authentication methods, conducting high-volume Microsoft Graph activity, downloading from SharePoint and OneDrive, and collecting mailbox content via REST APIs. The vendor warned that attackers deliberately rotate infrastructure and use separate IP ranges for authentication, reconnaissance, and exfiltration to subvert simple network indicators.

Microsoft listed the typical objectives of a compromised identity:

  • Inventory users, groups, permissions, resources and accessible content across the tenant using the Graph API.
  • Inspect roles and high-value accounts for privilege escalation.
  • Enumerate mailbox messages, folders, and attachment metadata for intelligence collection.
  • Conduct sustained, high-volume downloads from SharePoint Online, OneDrive for Business, and—in some cases—Exchange Online.
  • Carry out data exfiltration lasting hours to multiple days depending on volume.

“The attack underscores a critical detection challenge: Microsoft Graph abuse rarely appears suspicious when viewed through a single API call,” Microsoft said, urging holistic, behavior-focused correlation across Graph activity.

Attribution, shared infrastructure, and the loose-knit criminal ecosystem

Microsoft linked initial access activity in these campaigns to a range of actors, naming Storm-3121 and Storm-3032 in its analysis. The activity overlaps with a loose-knit set of cybercrime actors tracked under labels such as Cordial Spider, O-UNC-045, PREY-0058, and UNC6671.

Security researchers have described UNC6671 as using credential-harvesting panels on generic root domains that masquerade as passkey services and append victim-specific subdomains to tailor voice-phishing campaigns. Microsoft said Storm-3121’s initial access has led to ShinyHunters and Falcon (aka CL-CRI-1182) extortion activity, while Storm-3032 is its designation for UNC6671 — a group that reportedly broke off from BlackFile (aka CL-CRI-1116) and now runs under the Helix extortion brand.

Although Microsoft noted the exact connections between these labels are unclear, it observed overlap in shared initial-access playbooks, commoditized phishing panels, voice-phishing callers, and infrastructure used by splintered affiliates.

What this means for technologists, finance teams, and end users

  • Technologists and security teams: prioritize holistic Graph activity monitoring and cross-event correlation, watch for newly registered authentication methods (phone numbers, authenticator apps), and track suspicious domain registrations that employ company-specific subdomains.
  • Accounts payable and procurement leaders: treat emailed approvals and invoice threads that include executive signatures as high-risk when they request ACH transfers; verify approvals through established, out-of-band channels before moving funds.
  • End users and employees: be wary of unsolicited calls or messages to personal phones claiming to be IT, and treat passkey or SSO update prompts received via SMS or Teams with skepticism—attackers are using those exact pretexts to initiate AitM and device-code flows.

These campaigns show attackers layering mass fraud and targeted identity deception to convert a single social-engineering prompt into sustained tenant access and data exfiltration. As Microsoft emphasized, spotting malicious behavior in Graph traffic requires looking at patterns over time rather than isolated API calls — a detection problem that will shape defensive priorities in the weeks ahead.

https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html