By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Passkey Phishing Steals Microsoft 365 Data
Microsoft has reported that threat actors are employing social engineering tactics centered around passkey and single sign-on (SSO) themes to compromise corporate Microsoft accounts and exfiltrate data from Microsoft 365 services. These attacks are attributed to various extortion gangs, including ShinyHunters and Helix. The attackers are leveraging the growing adoption of passkeys, a passwordless authentication method, and the convenience of SSO to trick users into revealing their credentials or granting unauthorized access. By impersonating legitimate services or communications related to these authentication methods, threat actors aim to bypass traditional security measures that might flag suspicious login attempts. Once access is gained, the compromised accounts are used to steal sensitive information stored within Microsoft 365, which can include emails, documents, customer data, and proprietary business information. The sophistication of these attacks lies in their ability to mimic trusted communications, making it difficult for even security-aware users to distinguish between legitimate requests and phishing attempts. Microsoft has not disclosed the exact volume of data stolen or the number of organizations affected, but the advisory highlights a significant shift in attack vectors targeting cloud-based productivity suites. The company is urging customers to implement robust security practices, including multi-factor authentication (MFA) beyond passkeys where applicable, regular security awareness training for employees, and vigilant monitoring of account activity for any unusual patterns. The rise of passkey-themed phishing underscores the evolving landscape of cyber threats, where attackers adapt their methods to exploit new technologies and user behaviors. Organizations relying on Microsoft 365 are advised to review their security configurations and ensure they are protected against these sophisticated social engineering campaigns. The involvement of known extortion gangs like ShinyHunters and Helix suggests a potential for further data leaks or demands for ransom if the compromised data is deemed valuable. This development necessitates a proactive approach to cybersecurity, focusing on user education and the deployment of advanced threat detection and response capabilities to safeguard sensitive corporate assets within cloud environments. The effectiveness of these attacks is amplified by the increasing reliance on cloud services for business operations, making the security of platforms like Microsoft 365 a critical concern for organizations worldwide. Microsoft's advisory serves as a crucial warning to businesses to bolster their defenses against these targeted phishing operations that exploit the trust placed in modern authentication methods.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.