search

LEMON BLOG

Microsoft Warns of Passkey Phishing Campaigns Targeting Cloud Accounts and Sensitive Business Data

Microsoft has detailed two major threat campaigns that show how social engineering is becoming more sophisticated as attackers combine trusted infrastructure, executive impersonation, and modern authentication workflows. One campaign focused on large-scale financial fraud, while the other targeted Microsoft cloud identities using convincing passkey and multi-factor authentication lures. In both cases, the attackers were not relying on obvious malware attachments or crude phishing pages. Instead, they built believable scenarios around legitimate business processes and used those narratives to persuade employees into either sending money or granting access to corporate accounts.

The campaigns also highlight an important shift in identity-focused attacks. Passkeys and stronger authentication methods are designed to reduce the risk of traditional password theft, but attackers are increasingly adapting by targeting the people using those systems rather than the technology itself. If an employee can be convinced to approve an authentication request, register a new method, or complete a device-code flow on behalf of an attacker, even strong authentication controls can be undermined.

A Million Scam Emails Sent in Just Three Days

The first campaign was a large-scale financial fraud operation that sent more than one million scam emails between 3 and 5 August 2026. Attackers impersonated senior executives such as CEOs and attempted to convince accounts payable staff that payments needed to be made for a supposed annual ServiceNow subscription. The requested payments were structured as Automated Clearing House, or ACH, transfers, directing money toward accounts controlled by the attackers.

Microsoft said the campaign primarily targeted enterprise organisations in the United States across industries including IT services, consumer goods, real estate, and discrete manufacturing. Rather than sending a simple fake invoice and hoping someone paid it, the attackers created a much more complete story around each request. The emails included executive names, vendor branding, fabricated invoices, and supposed approval conversations that made the payment request appear as though it had already passed through normal internal processes.

This layered approach is important because employees are generally becoming more cautious about obvious invoice scams. By showing what appears to be an existing conversation between senior management and a supplier, attackers can create the impression that the recipient is merely completing the final administrative step rather than making a major financial decision. That reduces hesitation and can make the request feel routine.

Generative AI May Have Helped Personalise the Fraud

Microsoft believes generative AI was likely used to help create the email templates and customise messages for different organisations. The attackers appear to have researched senior personnel at their targets, identifying CEOs, CFOs, presidents, and other executives before inserting their names and contact details into forged signatures and conversations. This allowed each email to look much more specific to the company receiving it instead of resembling a generic mass-phishing message.

The ability to personalise fraud at scale is one of the more significant ways generative AI can assist cybercriminals. Creating a convincing executive impersonation campaign manually across hundreds or thousands of organisations would normally require considerable time, especially if the attacker wants each message to reference the right names, company structure, and vendor relationships. AI can reduce that workload by rapidly generating variations while maintaining a consistent and professional tone.

The attackers also registered domains intended to look connected to legitimate services or business functions. Microsoft highlighted domains such as service-nowinc[.]com and domainlify[.]net as examples associated with the activity. When combined with polished emails and forged conversation histories, domains that appear superficially plausible can make the fraud much harder for a busy finance employee to recognise immediately.

The Second Campaign Goes After Microsoft Cloud Identities

The second campaign is arguably more concerning because the attackers are targeting authentication itself. Microsoft has been tracking the activity since May 2026, observing compromised accounts followed by suspicious sign-ins, new authentication methods being registered, and large amounts of activity involving Microsoft Graph, SharePoint, OneDrive, and Exchange Online.

The attacks typically begin with direct contact. Employees may receive a phone call or message on their personal number from someone pretending to be part of the organisation's IT help desk. The caller then creates urgency by claiming that the employee must immediately update a passkey, MFA configuration, or single sign-on setting to avoid losing access to company systems.

Victims are subsequently directed to counterfeit websites designed to resemble Microsoft authentication pages. These sites may be delivered through SMS messages sent to the employee's personal device, which can make the interaction feel more believable because help desks sometimes legitimately contact staff through multiple channels. The attacker then guides the victim through an authentication process that ultimately grants access to the attacker instead.

Passkey Phishing Does Not Necessarily Mean Stealing a Passkey

The term "passkey phishing" can be slightly misleading if interpreted as attackers simply stealing a passkey in the same way they steal a password. Modern passkeys are specifically designed to resist traditional phishing because they are tied to legitimate websites and do not expose reusable credentials in the same way passwords do. Attackers therefore focus on manipulating the surrounding authentication process.

Microsoft observed adversary-in-the-middle techniques and device-code authentication flows being used to take control of accounts. In a device-code attack, the victim can be tricked into entering a legitimate authentication code or approving a legitimate Microsoft sign-in that is actually associated with the attacker's session. The employee successfully authenticates with Microsoft, but the access is granted to the wrong party.

This creates a dangerous situation because the attacker does not necessarily need to steal the user's password or session cookie. The victim effectively completes the authentication process for them. As a result, MFA can still be present and technically functioning while the account is nevertheless compromised through social engineering.

Attackers Are Researching Employees Before Making Contact

Microsoft says the operators appear to conduct substantial preparation before contacting victims. Public sources such as professional networking platforms, company websites, and social media can reveal an employee's role, contact information, reporting relationships, and the names of senior executives. That information makes a fake help-desk call much more convincing because the attacker can speak with specific knowledge of the organisation.

In some cases, attackers have also used already-compromised corporate accounts to contact additional employees through Microsoft Teams. A message arriving from a colleague or internal account naturally carries more credibility than an unknown external sender, allowing the campaign to spread further inside an organisation. This means one compromised identity can become the starting point for additional social-engineering attempts.

The infrastructure used in these attacks is equally targeted. Attackers have registered domains themed around passkeys, SSO configuration, identity verification, and account activation, including passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, integratedsso[.]com, and several others. They may then place the victim company's name in a subdomain, producing addresses that appear customised specifically for that organisation.

Links to a Wider Cybercrime Ecosystem

The techniques observed by Microsoft overlap with activity attributed by researchers to a loose network of financially motivated cybercriminals tracked under names including Cordial Spider, O-UNC-045, PREY-0058, and UNC6671. These groups appear to share phishing infrastructure, extortion techniques, access methods, or supporting services even when they operate under different names.

Mandiant has previously described UNC6671 as using credential-harvesting panels hosted on generic domains that resemble passkey or identity services. Victim-specific company names are then added as subdomains, allowing attackers to reuse the same underlying infrastructure while making each phishing site appear custom-built for a particular target. This approach is efficient because the technical platform can be reused repeatedly while the visible branding changes from victim to victim.

The exact relationships among the groups are still unclear. Some may represent splintered affiliates that previously worked together, while others could simply be purchasing access to the same phishing kits, voice-phishing services, or infrastructure providers. Modern cybercrime increasingly functions like a service economy, where different specialists provide phishing panels, initial access, social-engineering callers, data theft, or extortion capabilities.

Microsoft Connects the Activity to Storm-3121 and Storm-3032

Microsoft has linked the initial-access activity it observed to multiple threat actors, including Storm-3121 and Storm-3032. Storm-3121 has been associated with compromises that ultimately lead to extortion activity involving ShinyHunters and a group Microsoft tracks as Falcon. Storm-3032, meanwhile, is Microsoft's designation for UNC6671, which reportedly includes actors who split from a group known as BlackFile and now operate under the Helix extortion brand.

These distinctions can become confusing because different cybersecurity companies often assign their own names to the same or overlapping groups. The important point is that the passkey-themed attacks do not appear to be isolated experiments. They fit into a broader ecosystem of organised cybercrime where initial account compromise can eventually lead to large-scale data theft and extortion.

Once an attacker gains access to a corporate identity, the objective shifts quickly from authentication to persistence and data discovery. Microsoft observed compromised accounts being used to expand access into SharePoint Online, OneDrive, Exchange Online, and other services available through Microsoft Graph. In some cases, the attackers performed extremely high volumes of API activity as they searched for valuable information across the tenant.

Attackers Register Their Own MFA to Make Access Persistent

One of the most important behaviours Microsoft observed happens shortly after the initial compromise. Rather than relying indefinitely on stolen credentials or a single hijacked session, the attackers attempt to register an authentication method they control on the victim's account. This could be a new phone number, authenticator application, or software-based one-time password token.

Doing so changes a temporary compromise into something much more persistent. Even if the victim later changes their password, an attacker-controlled authentication factor may still provide another route into the account unless administrators notice and remove it. Combined with active sessions or credentials that have not yet been revoked, this can allow the attacker to keep returning without needing the victim to cooperate again.

This behaviour also shows why organisations need to monitor authentication-method changes just as closely as login events. A successful sign-in from an unfamiliar location may be investigated, but a newly registered MFA factor can be even more important because it represents a deliberate attempt to establish long-term control over the identity.

Microsoft Graph Becomes a Powerful Tool After Compromise

After obtaining persistent access, attackers can use Microsoft Graph to explore the organisation at considerable scale. Graph provides legitimate APIs for interacting with Microsoft 365 services, which means activity conducted through it can look like normal application behaviour when examined one request at a time.

Microsoft observed attackers using Graph to enumerate users, groups, permissions, resources, and other information available to the compromised identity. They also inspected high-value accounts and service identities that might provide opportunities for privilege escalation. Mailbox folders, messages, and attachment metadata could be collected to understand internal relationships, ongoing projects, financial information, and other potentially valuable material.

The same access can then be used to download large amounts of content from SharePoint Online and OneDrive for Business. In some cases, Exchange Online data was targeted as well. Data collection could continue for several hours or even multiple days depending on the amount of information accessible through the compromised account.

Data Exfiltration Can Look Like Normal Cloud Activity

One of the biggest detection challenges is that most of these actions use legitimate Microsoft services. Downloading a file from OneDrive, reading an email, querying Microsoft Graph, or accessing SharePoint is not automatically suspicious. Employees and applications perform the same actions every day.

The malicious pattern only becomes visible when those events are viewed together. An unusual sign-in followed by a new MFA registration, rapid Graph enumeration, large-scale SharePoint downloads, and mailbox collection creates a very different picture than any one of those actions viewed separately. This is why Microsoft emphasises behavioural progression and cross-event correlation rather than attempting to detect the campaign through one specific API request.

Attackers also deliberately rotate their network infrastructure during different phases of the intrusion. One IP address may be used for authentication, another for reconnaissance, and another for data exfiltration. This makes simple IP-based blocking or alerting much less reliable and further reinforces the need to look at identity behaviour as a complete sequence.

Strong MFA Alone Cannot Solve a Social-Engineering Problem

The campaign is an important reminder that stronger authentication does not eliminate phishing; it changes what attackers need to phish for. Password-based phishing aims to obtain a credential. MFA phishing tries to convince users to approve authentication. Device-code attacks try to make victims authorise someone else's session, while passkey-themed scams can manipulate users into enrolling or changing authentication settings.

Organisations therefore need to combine technical controls with clear operational procedures. Employees should know that legitimate IT staff should not unexpectedly ask them to update authentication methods through links received by SMS or personal messaging services. Help-desk processes should also make it easy for staff to independently verify whether an authentication request is genuine without relying on the contact details supplied by the person making the request.

Restrictions around authentication-method registration can provide another important safeguard. High-risk changes such as adding a phone number or authenticator should be monitored closely, especially when they occur shortly after an unusual login or originate from an unmanaged device. Organisations may also want stronger controls around device-code authentication where it is not operationally necessary.

The Financial Fraud Campaign Shows the Same Human Weakness From Another Angle

Although the invoice scam and passkey campaign use very different technical methods, they ultimately target the same weakness: trust. Finance employees are expected to act on instructions from senior executives, while ordinary employees are expected to cooperate with the IT help desk. Attackers succeed when they can convincingly insert themselves into those trusted relationships.

The first campaign built trust through executive names, forged approval threads, and familiar vendor branding. The second built it through urgency, technical language, and the appearance of legitimate Microsoft authentication. Both campaigns demonstrate why simply telling employees to "watch for phishing" is no longer enough.

Modern security awareness needs to focus on business processes. Finance staff should understand that payment destination changes or unexpected ACH requests require independent verification. Employees should understand that authentication changes must be initiated through known internal channels rather than links provided by unsolicited callers or messages.

Generative AI Is Making Social Engineering Easier to Scale

The use of generative AI in the financial fraud campaign is another indication of how quickly cybercrime is evolving. AI can produce professionally written emails, adapt messages to different industries, generate fake conversation histories, and remove many of the grammar or formatting mistakes that once made phishing easier to spot.

It can also dramatically reduce the cost of personalisation. Attackers can gather public information about executives and employees, then automatically produce hundreds or thousands of targeted messages using those details. What once required substantial manual work can increasingly be automated.

This does not mean AI automatically makes every phishing campaign successful. Organisational controls, payment verification, identity monitoring, and well-trained employees can still stop these attacks. What changes is the scale at which convincing deception can be produced and tested.

Final Thoughts

Microsoft's findings show that identity attacks are moving beyond simple password theft. Attackers are learning how to exploit the entire authentication experience, including passkeys, MFA enrolment, device-code flows, help-desk procedures, and the trust employees place in familiar Microsoft interfaces. Once a cloud identity is compromised, legitimate tools such as Microsoft Graph can then be turned into highly effective mechanisms for reconnaissance and large-scale data collection.

The most concerning behaviour may be the rapid registration of attacker-controlled MFA methods. That allows criminals to convert a momentary social-engineering success into persistent access that can survive long after the original phishing interaction. Organisations should therefore treat unexpected authentication-method changes, unusual unmanaged-device sign-ins, and sudden high-volume Graph activity as connected indicators rather than unrelated events.

The separate CEO impersonation campaign reinforces the same lesson from a financial perspective. Attackers increasingly build complete narratives rather than sending isolated phishing messages, combining executive identities, vendor branding, fake invoices, realistic email threads, and AI-assisted personalisation to make fraudulent requests feel routine. Controls that require independent verification outside the original email conversation remain essential.

Passkeys and modern MFA are still significantly stronger than relying on passwords alone, but no authentication technology can completely protect a user who is manipulated into authorising the attacker themselves. As cloud environments become more important to everyday business operations, security teams will need to monitor not only whether an authentication succeeded, but how it happened, what changed immediately afterward, and what the identity began doing once access was granted.

Microsoft Rushes Out Emergency Windows Update Afte...
Homebrew 7.0.0 Arrives With a Native GUI, Built-In...

Related Posts

 

Comments 0

Loading latest comments...
Tuesday, 15 September 2026

Captcha Image

LEMON VIDEO CHANNELS

Step into a world where web design & development, gaming & retro gaming, and guitar covers & shredding collide! Whether you're looking for expert web development insights, nostalgic arcade action, or electrifying guitar solos, this is the place for you. Now also featuring content on TikTok, we’re bringing creativity, music, and tech straight to your screen. Subscribe and join the ride—because the future is bold, fun, and full of possibilities!

My TikTok Video Collection