VMTech
Discuss a project

Microsoft details passkey phishing campaign targeting cloud identities

Microsoft details passkey phishing campaign targeting cloud identities

Passkey lures used to compromise Microsoft cloud accounts

Microsoft has described a cloud intrusion campaign detected since May 2026 in which threat actors use passkey-themed social engineering to take over multiple accounts, add attacker-controlled authentication methods and collect cloud data. The activity included high-volume Microsoft Graph operations, downloads from SharePoint and OneDrive, and mailbox collection through REST APIs.

The campaign begins with identity-focused contact aimed at employees’ personal phone numbers. Attackers call or message targets while claiming to represent an organisation’s IT help desk, then urge an immediate passkey, multi-factor authentication or single sign-on update to prevent disruption. SMS messages direct victims to counterfeit websites made to resemble the Microsoft sign-in experience.

Microsoft said the objective is to guide users through adversary-in-the-middle or device-code authentication flows. That can let the operator capture credentials or cause the victim to grant access on the actor’s behalf. In a smaller number of cases, already compromised accounts were used to spread similar passkey-themed messages through Microsoft Teams.

Persistence follows initial access

Observed malicious domains used themes including passkeys, SSO enrolment, account activation and identity verification. They also incorporated a target organisation’s name as a subdomain, a pattern designed to support targeted voice-phishing activity. Microsoft attributed initial-access activity in this campaign to several actors, including Storm-3121 and Storm-3032.

In one investigation, an anomalous sign-in to Microsoft Office Home from an unmanaged device was followed by access to SharePoint Online and OneDrive through the Graph API. The actor enumerated sensitive files and internal services. In another case, a passkey lure initiated device-code phishing that gave the attacker control of an account without stealing credentials or cookies, bypassing MFA safeguards.

A third pattern involved credentials likely compromised in an earlier event. The attackers registered their own phone-based method, then conducted reconnaissance and post-exploitation activity. Microsoft said the first post-compromise objective was to turn temporary access into a persistent foothold by enrolling a phone number, authenticator application or software-based one-time-password token under the actor’s control.

Cloud telemetry needs correlated analysis

Once established, the attacker can use the compromised identity to inventory users, groups, permissions, resources and accessible tenant content through Microsoft Graph. The activity can also include inspecting privileged roles and service identities, enumerating mailbox content and metadata, and downloading material from SharePoint Online, OneDrive for Business and, in some cases, Microsoft Exchange Online.

Microsoft noted that exfiltration can continue for hours or days, while operators rotate infrastructure and use separate IP addresses for authentication, reconnaissance and data transfer. Individual Graph API calls may appear legitimate in isolation, making behavioural progression and cross-event correlation critical for detection.

For businesses, the practical implication is to investigate unusual sign-ins, new authentication-method registrations and bulk cloud-data access as connected events, while ensuring employees have a clear verification path for any alleged IT request to change passkey, MFA or SSO settings.

#cloudsecurity#phishing#identitysecurity#microsoft
Open analytics
On the site 3 views
min read 4 13.09.2026
Instagram

Microsoft details passkey phishing campaign targeting cloud identities

Open the post on Instagram ↗