Cybersecurity
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts
Cyber RTSeptember 15, 20263 min read

Microsoft has revealed two cyber campaigns exploiting third-party email systems for financial fraud and social engineering to breach cloud environments. The first campaign involved sending over a million scam emails impersonating CEOs to trick companies into making ACH transfers. The second campaign targeted cloud accounts using passkey-themed social engineering, leading to unauthorized access and data exfiltration. Both campaigns utilized generative AI and sophisticated impersonation tactics.
Microsoft has revealed two sophisticated cyber campaigns exploiting third-party email delivery systems and social engineering tactics to perpetrate financial fraud and cloud environment breaches. The first campaign involved sending over a million scam emails in early August 2026, impersonating CEOs of targeted companies to deceive accounts payable departments into making fraudulent Automated Clearing House (ACH) transfers for a fake ServiceNow subscription. The attackers used generative AI to craft convincing email templates tailored to their victims, focusing primarily on U.S. enterprises in various sectors.
The scam emails were meticulously designed to look authentic, incorporating elements like executive impersonation, vendor branding, and fabricated invoices. The attackers registered impersonation domains and sent payment requests through trusted infrastructure, embedding fake invoices and email threads to persuade finance personnel to initiate ACH transfers. This multi-layered approach aimed to reduce skepticism among recipients, making the deception more effective.
In a strategic move, the attackers included the names and email addresses of real CEOs, CFOs, and presidents in the email signatures, enhancing the credibility of the messages. They also registered bogus domains mimicking trusted brands and individuals, such as service-nowinc[.]com and domainlify[.]net, to further legitimize their fraudulent communications.
The second campaign, documented by Microsoft, involved cloud-based intrusions using passkey-themed social engineering tactics. Starting in May 2026, threat actors targeted multiple accounts, adding their authentication methods and engaging in high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and mailbox collection through REST APIs. The attack often began with identity-focused social engineering, where attackers contacted users via phone, posing as IT help desk personnel, and urged them to update their passkey or multi-factor authentication (MFA) settings.
Victims were redirected to counterfeit websites mimicking Microsoft's sign-in experience, where attackers employed adversary-in-the-middle (AitM) techniques to capture credentials or gain unauthorized access. The attackers conducted extensive pre-attack research, gathering information from public sources to tailor their approach. In some cases, they exploited already compromised accounts to spread passkey-themed messages via Microsoft Teams.
The threat actors registered domains related to passkeys and identity verification, incorporating target organization names as subdomains to facilitate targeted phishing campaigns. This modus operandi aligns with a cybercrime group tracked by the cybersecurity community under various monikers, including Cordial Spider and UNC6671. These actors share infrastructure and phishing tactics, suggesting a coordinated effort among splintered affiliates.
Microsoft attributed the initial access activities to threat actors like Storm-3121 and Storm-3032, with connections to groups like ShinyHunters and Falcon. The attackers aimed to transform temporary compromises into persistent footholds by enrolling their MFA methods, allowing them to maintain access without victim participation. They conducted extensive reconnaissance using the Graph API, inspecting roles and high-value accounts, and engaging in sustained data exfiltration from SharePoint Online, OneDrive, and Microsoft Exchange Online.
The campaigns highlight the challenges in detecting Microsoft Graph abuse, which often appears benign when viewed through individual API calls. Microsoft emphasizes the need for holistic assessment of Graph activity, focusing on behavioral progression and cross-event correlation to identify suspicious patterns. These incidents underscore the evolving tactics of cybercriminals and the importance of robust security measures to protect against sophisticated threats.


