Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft recently revealed details of two cybercrime campaigns involving the exploitation of third-party email infrastructure to conduct financial fraud scams and using passkey-themed social engineering to compromise cloud environments.

The first campaign saw threat actors sending over a million scam emails between August 3 and 5, 2026, posing as CEOs of target companies to convince accounts payable departments to initiate Automated Clearing House transfers for a supposed ServiceNow annual subscription. The operators utilized generative AI to create tailored email templates for enterprise users in various sectors in the U.S.

The second campaign focused on cloud-based intrusions targeting multiple accounts through identity-focused social engineering. The attackers manipulated users into updating their passkey, multi-factor authentication, or single sign-on configurations to gain access to Microsoft accounts. They also registered domains related to passkeys and identity verification to deceive employees.

Both campaigns exhibited sophisticated tactics to deceive victims and gain access to sensitive information. Microsoft identified various threat actors involved in these activities, emphasizing the importance of holistic assessment of Graph API abuse for effective detection.

Overall, these campaigns highlight the evolving nature of cyber threats and the need for robust security measures to protect organizations from such malicious activities.