highPhishing

Passkey-Themed Phishing Campaign Targeting Microsoft 365 Accounts

First seen Sep 12, 2026 · Updated Sep 12, 2026

phishingsocial-engineeringmicrosoft-365credential-theftshinyhuntersextortionidentity-securityagent-relevant

Threat actors linked to ShinyHunters, Helix, and other extortion groups are conducting social engineering campaigns that abuse passkey and single sign-on registration flows to compromise corporate Microsoft 365 accounts. Stolen credentials and session data are used to exfiltrate sensitive organizational data for extortion purposes.

Technical Analysis

Attackers impersonate IT support or SSO/passkey enrollment prompts to trick users into authorizing malicious passkey registrations or divulging authentication codes, effectively bypassing traditional MFA protections by abusing trust in passwordless authentication UX. Once account access is obtained, attackers leverage legitimate Microsoft 365 session tokens and OAuth grants to access mailboxes, SharePoint, and Teams data, often exfiltrating data via Graph API calls to avoid detection. The campaign mirrors known ShinyHunters/Scattered Spider tactics of help-desk impersonation and MFA fatigue, now adapted to newer passwordless authentication mechanisms. Organizations using Microsoft 365 integrations for AI agent workflows (e.g., Copilot, Graph API-connected RAG pipelines, or agent frameworks with stored OAuth tokens) face elevated risk, as compromised credentials or session tokens could allow attackers to exfiltrate data accessible to those agents or hijack agent-to-service authentication paths.

Affected Systems

Microsoft 365 (Exchange Online, SharePoint, Teams), Entra ID (Azure AD) passkey/FIDO2 and SSO enrollment flows, corporate identity federation configurations

Indicators of Compromise

  • Phishing domains impersonating Microsoft SSO/passkey enrollment pages (specific domains not disclosed in source)
  • Fraudulent IT helpdesk emails referencing passkey setup
  • Anomalous OAuth app consent grants in Entra ID audit logs
  • Unusual Microsoft Graph API data exfiltration patterns

Remediation Steps

  1. 1

    Enforce phishing-resistant authentication policies

    Restrict passkey/FIDO2 enrollment to managed devices and require verification through a secondary trusted channel before allowing new passkey registrations.

  2. 2

    Audit Entra ID sign-in and consent logs

    Review conditional access and OAuth application consent logs for anomalous SSO enrollments, new device registrations, or unusual application permissions granted to user accounts.

  3. 3

    Train staff on help-desk impersonation tactics

    Educate employees and IT support staff to verify identity through out-of-band channels before assisting with passkey resets or SSO account changes.

  4. 4

    Monitor Microsoft Graph API activity

    Deploy detection rules for abnormal Graph API calls, bulk mailbox/file access, and data exfiltration patterns tied to compromised accounts, including those used by AI agents or automation pipelines with Microsoft 365 access.

  5. 5

    Rotate and scope down OAuth tokens/API keys

    Revoke and reissue OAuth tokens and application credentials used by agents or integrations connected to Microsoft 365, applying least-privilege scopes.

Industries Most Exposed

Cross-industry (enterprise Microsoft 365 users)financial servicestechnologyretailhealthcare

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.