Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft disclosed two distinct threat campaigns: one using AI-generated CEO impersonation emails to execute ACH fraud, and another leveraging passkey-themed social engineering to compromise cloud accounts The first campaign sent over a million scam emails between August 3-5, 2026, targeting U.S. enterprise accounts payable departments across IT services, consumer goods, real estate, and manufacturing sectors The second campaign, active since May 2026, uses voice phishing and SMS to trick emplo
Analysis
TL;DR
- Microsoft disclosed two distinct threat campaigns: one using AI-generated CEO impersonation emails to execute ACH fraud, and another leveraging passkey-themed social engineering to compromise cloud accounts
- The first campaign sent over a million scam emails between August 3-5, 2026, targeting U.S. enterprise accounts payable departments across IT services, consumer goods, real estate, and manufacturing sectors
- The second campaign, active since May 2026, uses voice phishing and SMS to trick employees into updating passkeys/MFA on counterfeit Microsoft sign-in pages, enabling adversary-in-the-middle attacks
- Threat actors are increasingly combining generative AI with layered social engineering narratives, moving beyond single-lure scams to unified deceptive stories incorporating executive impersonation, vendor branding, fabricated invoices, and forged email threads
- The passkey phishing campaign overlaps with the UNC6671 collective (also tracked as Cordial Spider, O-UNC-045, PREY-0058), which shares commoditized phishing infrastructure, voice-phishing callers, and initial access playbooks across splintered affiliates
Why It Matters
This disclosure highlights a significant escalation in how threat actors are weaponizing generative AI and social engineering to bypass traditional security controls, making phishing attacks more personalized, credible, and harder to detect. For AI and security practitioners, it underscores the critical importance of verifying authentication requests through out-of-band channels and implementing robust email and identity governance policies. The convergence of AI-assisted content generation with adversary-in-the-middle techniques represents a growing threat vector that organizations must address proactively.
Technical Details
AI-Enhanced CEO Impersonation Campaign: Threat actors registered impersonation domains (e.g., service-nowinc[.]com, domainlify[.]net) and used generative AI to create tailored email templates and drafts. The campaign layered executive impersonation, vendor branding (ServiceNow), fabricated invoices, forged approval emails, and supporting email conversations into a unified narrative to reduce recipient skepticism. Targets were identified by scraping CEO, CFO, and president names from public sources and inserting them into email signatures.
Passkey Phishing via Adversary-in-the-Middle (AitM): The second campaign begins with voice phishing or SMS messages claiming to be from IT help desks, urging users to update passkeys, MFA, or SSO configurations. Victims are redirected to counterfeit Microsoft sign-in pages that capture credentials or force device-code authentication flows, allowing attackers to maintain persistent access even after password changes.
Infrastructure and Domain Patterns: Attackers registered domains using themes like passkeys, SSO enrollment, account activation, and identity verification, often appending victim organization names as subdomains (e.g.,
<company>.passkeyhelpdesk[.]com). Proxy-associated infrastructure was used for automated collection from compromised cloud identities via Microsoft Graph APIs, SharePoint, and OneDrive.Threat Actor Attribution: Microsoft attributed initial access activity to Storm-3121 (leading to ShinyHunters and Falcon extortion) and Storm-3032 (linked to UNC6671, a splinter group from BlackFile operating under the Helix extortion brand). The loose-knit collective shares commoditized phishing panels, voice-phishing operations, and initial access playbooks across affiliates.
Data Exfiltration Tactics: Post-compromise activity includes high-volume Microsoft Graph API calls, SharePoint and OneDrive downloads, and mailbox collection through REST APIs, indicating automated, large-scale data harvesting from breached cloud environments.
Industry Insight
- Organizations should implement strict verification protocols for payment requests, requiring out-of-band confirmation for any ACH or wire transfer instructions, especially those involving vendor subscriptions or urgent executive directives. Security awareness training must emphasize that no legitimate IT department will request passkey or MFA updates via unsolicited phone calls or SMS.
- The commoditization of phishing infrastructure and shared playbooks among cybercrime collectives means that defensive strategies cannot rely on signature-based detection alone. Zero-trust identity architectures, continuous authentication monitoring, and behavioral analytics are essential to detect anomalous sign-in patterns and unauthorized authentication method additions.
- As generative AI lowers the barrier to creating convincing phishing content at scale, enterprises should invest in AI-driven email security solutions capable of detecting subtle narrative inconsistencies, deepfake audio cues, and domain spoofing techniques that go beyond traditional header analysis.
Disclaimer: The above content is generated by AI and is for reference only.