highPhishing

Passkey Phishing Campaign Targeting Microsoft Cloud Accounts

First seen Sep 14, 2026 · Updated Sep 14, 2026

phishingmicrosoft365cloud-account-takeoversocial-engineeringpasskey-abusebusiness-email-compromisecredential-theft

Microsoft disclosed two related campaigns abusing third-party email infrastructure and passkey-themed social engineering to compromise Microsoft cloud accounts. One campaign sent over a million financial fraud scam emails impersonating CEOs, while the other used fake passkey registration prompts to hijack cloud accounts and exfiltrate data.

Technical Analysis

The campaigns leverage legitimate third-party email delivery services to bypass reputation-based spam filters, sending large volumes of CEO-impersonation fraud emails to trigger wire transfers or credential entry. In parallel, attackers deploy passkey-themed phishing pages that mimic Microsoft's passkey enrollment flow, tricking users into registering attacker-controlled authenticators or approving malicious device bindings, effectively bypassing traditional MFA and phishing-resistant authentication assumptions. Once account access is achieved, attackers pivot to data exfiltration within Microsoft 365 environments, including mailbox and file storage content. Organizations that use Microsoft 365 accounts to store API keys, service credentials, or connect to AI agent orchestration platforms (e.g., Copilot Studio, Power Automate agents, or custom RAG pipelines authenticated via Entra ID) face risk of credential and secrets exposure if compromised accounts have access to agent configuration data or automation connectors.

Affected Systems

Microsoft 365 / Entra ID cloud accounts, passkey/WebAuthn enrollment workflows, third-party email delivery/relay services used for outbound mail

Indicators of Compromise

  • Not disclosed in source reporting (no specific hashes, IPs, or domains provided)

Remediation Steps

  1. 1

    Verify passkey enrollment sources

    Educate users to only register passkeys through official Microsoft account security pages, never via emailed links, and enable admin alerts for new authenticator registrations.

  2. 2

    Harden conditional access policies

    Enforce sign-in risk-based conditional access, device compliance checks, and location restrictions for Entra ID accounts, especially for accounts with delegated automation or agent-service permissions.

  3. 3

    Audit email delivery infrastructure

    Review SPF/DKIM/DMARC configurations and monitor for spoofed executive communications routed through third-party mail relays.

  4. 4

    Rotate exposed credentials and API keys

    If compromise is suspected, rotate all secrets, API keys, and service principal credentials accessible from the affected mailbox or connected automation/agent tooling.

  5. 5

    Monitor for anomalous data exfiltration

    Enable Microsoft Purview/Cloud App Security alerts for unusual mailbox rule changes, bulk downloads, or new OAuth app consents following suspected account compromise.

Industries Most Exposed

financial servicestechnologyprofessional servicescross-industry (Microsoft 365 users)

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.