Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

  • Home
  • Blog
  • Attackers Use Passkey Phishing...
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
August 22, 2026Admin

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments.

More Than One Million Executive Impersonation Emails

According to Microsoft, the first campaign took place between August 3 and August 5, 2026, when attackers distributed more than one million fraudulent emails to enterprise users.

The messages impersonated CEOs and other senior executives and attempted to convince accounts payable personnel to initiate Automated Clearing House (ACH) transfers for a fabricated annual ServiceNow subscription.

Evidence collected by Microsoft indicates that the attackers used generative artificial intelligence to help create email templates and personalized messages tailored to individual recipients.

The campaign primarily targeted organizations in the United States across sectors including:

  • IT services;
  • Consumer goods;
  • Real estate;
  • Discrete manufacturing.

Rather than relying on a single phishing message, the operation combined executive impersonation, vendor branding, fabricated invoices, and forged email conversations into a coordinated social engineering scenario.

Attackers also researched the identities of CEOs, CFOs, and company presidents and inserted legitimate names and email addresses into message signatures to make the requests appear more credible.

Domains associated with the campaign included:

  • service-nowinc[.]com
  • domainlify[.]net

Passkey-Themed Social Engineering Targets Cloud Identities

The second campaign focused on compromising Microsoft cloud identities.

Microsoft has observed the activity since May 2026. Attacks commonly begin when threat actors contact employees through personal phone numbers using voice calls or SMS messages.

Posing as members of the organization's IT help desk, the attackers claim that users must urgently update their:

  • Passkey;
  • Multi-factor authentication configuration;
  • Single sign-on settings;
  • Or account authentication information.

Victims are then directed to counterfeit websites designed to imitate the legitimate Microsoft authentication experience.

The attackers may use Adversary-in-the-Middle (AitM) techniques or device-code phishing to gain control of Microsoft accounts. In some cases, this enables them to compromise an account without directly stealing the victim's password or browser cookies.

Attackers Register Their Own MFA Methods

Once initial access is obtained, the attackers attempt to convert the temporary compromise into a persistent foothold.

Instead of relying solely on stolen credentials, they register authentication methods under their own control, including:

  • New phone numbers;
  • Authenticator applications;
  • Software-based one-time password tokens.

An attacker-controlled second factor enables continued access to the corporate account without requiring further interaction from the legitimate user.

This persistence becomes particularly dangerous when combined with valid credentials or sessions that have not yet been revoked.

Microsoft Graph Used for Large-Scale Reconnaissance

Following account compromise, attackers have been observed generating high volumes of activity through the Microsoft Graph API.

Their actions can include:

  • Enumerating users, groups, permissions, and resources across the tenant;
  • Identifying privileged accounts and high-value service identities;
  • Reviewing mailbox messages, folders, and attachment metadata;
  • Downloading large volumes of data from SharePoint Online and OneDrive for Business;
  • Accessing Microsoft Exchange Online data;
  • Conducting sustained exfiltration over several hours or even multiple days.

Attackers may also rotate infrastructure throughout the attack lifecycle and use separate IP addresses for authentication, reconnaissance, and data exfiltration to make detection more difficult.

Phishing Infrastructure Customized for Each Victim

Microsoft observed multiple domains designed around passkey enrollment, SSO configuration, account activation, and identity verification themes, including:

  • passkeyhelpdesk[.]com
  • secure-passkey[.]com
  • setupmypasskey[.]com
  • add-passkey[.]com
  • integratedsso[.]com
  • oktasession[.]com
  • syncmykey[.]com
  • portalsetuphub[.]com

Attackers can include the target organization's name as a subdomain using a pattern such as:

<company>.<malicious-domain>[.]com

This approach helps make malicious URLs appear more relevant and trustworthy to targeted employees.

The activity overlaps with techniques associated with cybercrime clusters tracked under names including Cordial Spider, O-UNC-045, PREY-0058, and UNC6671.

Microsoft has also associated portions of the initial-access activity with threat actors it tracks as Storm-3121 and Storm-3032.

What Organizations Should Do

The campaigns demonstrate how modern identity attacks increasingly avoid traditional malware. Instead, attackers abuse people, authentication workflows, trusted infrastructure, and legitimate cloud APIs.

Organizations should consider the following defensive measures:

  • Independently verify payment requests and banking-detail changes;
  • Never update MFA or passkeys through links provided by unsolicited calls or SMS messages;
  • Monitor the registration of new MFA methods;
  • Detect sign-ins from unmanaged devices and unusual locations;
  • Monitor abnormal Microsoft Graph activity;
  • Alert on large-scale downloads from SharePoint, OneDrive, and Exchange;
  • Enforce strong Conditional Access policies;
  • Train employees to recognize phishing, vishing, and fake IT support scenarios.

A key detection challenge is that an individual Microsoft Graph API request may look completely legitimate. Security teams therefore need to correlate behavior across the full attack chain: suspicious authentication → new MFA registration → reconnaissance → high-volume cloud access → data exfiltration.

As generative AI makes phishing campaigns more convincing and personalized, protecting enterprise identities is becoming one of the most critical security priorities for Microsoft 365 and modern cloud environments.

Comments (0)

No comments yet.

Leave a Comment