Microsoft Warns of Passkey Phishing Cloud Attacks
Microsoft details two campaigns: one blasting CEO-impersonation invoice scams and another using passkey-themed social engineering to hijack Microsoft cloud

Microsoft has disclosed two distinct threat campaigns, one involving mass financial fraud emails and another using sophisticated passkey-themed lures to compromise cloud accounts and exfiltrate data. The first campaign sent over a million scam emails between August 3 and 5, 2026, while the second, detected since May 2026, uses social engineering to bypass multi-factor authentication.
According to Microsoft's Security Research team, the financial fraud campaign impersonated CEOs to target accounts payable departments. The goal was to trick employees into initiating Automated Clearing House (ACH) transfers for a fake ServiceNow annual subscription. The attackers used generative AI to craft tailored email templates.
"The campaign follows steps before and during the execution of the campaign: threat actors register impersonation domains, send executive-themed payment requests through trusted infrastructure, embed fabricated invoices and supporting conversations, and attempt to convince finance personnel to initiate ACH transfers," Microsoft said. The campaign layered executive impersonation, vendor branding, and fake documents to reduce recipient skepticism.
Campaign Infrastructure and Targets
The activity primarily targeted enterprise users in the United States across several sectors, including IT services, consumer goods, real estate, and discrete manufacturing. To appear legitimate, emails contained forged approval messages and fabricated email threads. Attackers identified specific high-level executives at victim organizations and inserted their names into email signatures.
The campaign relied on bogus domains designed to impersonate trusted brands. Microsoft provided examples of some registered domains used in the attacks.
Passkey Phishing for Cloud Access
The second campaign focuses on cloud intrusion. It begins with identity-focused social engineering, where threat actors call or message a user's personal phone number. Pretending to be from the organization's IT help desk, they urge the user to immediately update their passkey, MFA, or single sign-on configuration to avoid access disruptions.
Victims are redirected via SMS to counterfeit websites mimicking the legitimate Microsoft sign-in experience. The attackers use these sites to guide users through adversary-in-the-middle or device-code authentication flows. This allows them to capture credentials or get users to unknowingly grant access to their Microsoft accounts.
Microsoft notes the actors invest heavily in pre-attack research, gathering employee and organizational data from public sources like social networks. In some cases, they use already compromised accounts to send similar passkey-themed lures via Microsoft Teams.
The threat actors register domains built around security themes, often including the target organization's name as a subdomain. Microsoft listed several examples of these malicious domains.
Attack Attribution and Techniques
Microsoft links this passkey phishing activity to a loose-knit cybercrime collective tracked under names like Cordial Spider, O-UNC-045, PREY-0058, and UNC6671. The company attributes the initial access to threat actors it designates as Storm-3121 and Storm-3032. Storm-3032 is its designation for UNC6671, a group that broke off from the BlackFile extortion group and now operates under the Helix brand.
Following initial access, the attacker's first objective is to establish a persistent foothold. Instead of relying solely on stolen credentials, they enroll an MFA method under their control, such as a new phone number or authenticator app. This allows them to sign in without the victim's participation.
With this persistent access, threat actors can conduct extensive reconnaissance and data theft. They use the Microsoft Graph API to inventory users, groups, and permissions. They also enumerate mailbox content and engage in high-volume downloads from SharePoint Online and OneDrive for Business. Exfiltration can last from several hours to multiple days.
The attackers deliberately rotate their infrastructure, using separate IP addresses for authentication, reconnaissance, and exfiltration to evade detection. Microsoft warns that Graph API abuse is a critical detection challenge, as individual calls rarely appear suspicious. "This attack serves as a strong example of why Graph activity must be assessed holistically, with emphasis on behavioral progression and cross-event correlation rather than individual API requests in isolation," the company stated.





