HackMyIP
← Back to News
2026-09-13 The Hacker News

Microsoft Warns of Passkey Phishing Attacks Targeting Cloud Accounts

PhishingCloud SecurityAI Threats

Microsoft has disclosed two concurrent threat campaigns targeting enterprise users, one leveraging AI-generated CEO impersonation emails to steal funds via fraudulent ACH transfers, and another using passkey-themed social engineering to compromise Microsoft cloud accounts and exfiltrate sensitive data. The first campaign, detected between August 3 and 5, 2026, involved over one million scam emails sent through trusted third-party email delivery infrastructure. Attackers impersonated CEOs of target companies, urging accounts payable departments to process payments for a fake ServiceNow annual subscription. Microsoft noted the operators used generative AI to craft tailored email templates and drafted convincing narratives by layering executive impersonation, vendor branding, fabricated invoices, and forged internal email threads. Threat actors even researched the real names and email addresses of CEOs, CFOs, and presidents at victim organizations to make signatures appear legitimate. Targeted sectors included IT services, consumer goods, real estate, and discrete manufacturing, primarily in the United States. Researchers flagged the spoofed domain service-nowinc[.]com as one example; security teams can verify suspicious domains using a WHOIS lookup to expose registration details and ownership timelines that often reveal freshly created fraudulent infrastructure.

The second campaign, active since May 2026, focuses on cloud account takeovers through identity-focused social engineering that lures victims into enrolling attacker-controlled passkeys on their Microsoft accounts. Once authenticated, threat actors add their own authentication methods, conduct high-volume Microsoft Graph activity, and download data from SharePoint and OneDrive while harvesting mailboxes via REST APIs. Microsoft attributes the activity to automated collection from compromised cloud identities routed through proxy-associated infrastructure. The attacks follow a consistent pattern: suspicious sign-ins, MFA method manipulation, mass data download, and mailbox exfiltration, all designed to enable long-term espionage and data theft.

Defenders should treat any unsolicited request to register a new passkey or authentication factor as a red flag, particularly when initiated through an email link. Security teams are advised to audit recent MFA registrations, review Microsoft Graph and REST API logs for anomalous activity, and restrict third-party email forwarding that could be exploited to relay phishing payloads. Employees can confirm whether their credentials have appeared in known exposures via an email breach checker, while organizations should run a privacy checkup to identify exposed cloud configurations and identity policies that could be leveraged by attackers staging passkey phishing operations.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →