Interestana
Home/News/Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts

Microsoft has detailed two distinct cyberattack campaigns where threat actors leveraged third-party email delivery infrastructure and sophisticated social engineering tactics to compromise Microsoft cloud environments and exfiltrate sensitive data. The first campaign, disclosed by Microsoft, involved the distribution of over one million scam emails between August 3 and August 5, 2026. These emails impersonated chief executive officers, aiming to deceive recipients into engaging with financial fraud schemes. The attackers utilized compromised third-party email delivery services to send these fraudulent messages, thereby bypassing standard email security filters and reaching a wider audience.

The second, more targeted campaign focused on exploiting vulnerabilities related to passkeys, a passwordless authentication method. Threat actors employed passkey-themed social engineering, tricking users into believing they were interacting with legitimate passkey services. This deception was used to gain unauthorized access to Microsoft cloud accounts. Once access was established, the attackers proceeded to exfiltrate data from these compromised environments. Microsoft's investigation revealed that these attacks were part of a broader effort by financially motivated cybercriminal groups to gain access to cloud-based systems and extract valuable information.

Microsoft's security intelligence team identified that the attackers behind these campaigns were sophisticated, demonstrating an understanding of both email delivery infrastructure and emerging authentication technologies like passkeys. The use of third-party email services highlights a common tactic where attackers exploit legitimate services to mask their malicious activities and increase the likelihood of their phishing attempts reaching their targets. The passkey phishing attacks specifically targeted the trust users place in newer, more secure authentication methods, turning a security feature into a vector for compromise. This approach underscores the evolving nature of phishing attacks, which are increasingly adapting to new technologies and user behaviors.

In response to these incidents, Microsoft has implemented enhanced security measures and is actively working to disrupt the threat actors involved. The company emphasizes the importance of user vigilance and advises organizations to strengthen their security postures by implementing multi-factor authentication, regularly reviewing access logs, and educating employees about the latest phishing techniques. The detailed disclosure by Microsoft aims to inform the broader cybersecurity community and help other organizations defend against similar threats. The campaigns serve as a stark reminder that even advanced authentication methods can be targeted through social engineering if users are not adequately informed and protected.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next