Passkey-themed social engineering attacks lead to identity and cloud compromises, warns Microsoft Security

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Microsoft Security Research is tracking active cloud-based intrusions that have led to identity and cloud compromises. These attacks typically begin with unusual sign-ins followed by the addition of authentication methods by threat actors, high-volume activity on Microsoft Graph, and extensive downloads from SharePoint and OneDrive. The activity has been observed since May 2026 and is characterized by automated collection from compromised cloud identities using proxy-associated infrastructure. Organizations are advised to investigate this sequence across identity, Microsoft Graph, SharePoint, OneDrive, and Exchange signals, and to revoke sessions and remove unauthorized authentication methods for confirmed compromises. For more details, refer to the Microsoft Threat Intelligence Blog.

Attack Chain Overview

The attack chain begins with identity-focused social engineering, where attackers impersonate IT helpdesk personnel to create a sense of urgency regarding passkey or multifactor authentication (MFA) updates. Victims are directed to phishing sites that resemble legitimate Microsoft sign-in pages. This initial interaction often leaves little forensic evidence, complicating investigations.

Initial Access and User Identity Compromise

Attackers often utilize adversary-in-the-middle (AiTM) phishing techniques to capture credentials and session tokens. In some cases, they may also use device code phishing to gain unauthorized access. Once inside, they can access identity portals and management applications, leading to broader application access and potential data exfiltration.

High-Volume Data Collection and Exfiltration

Following reconnaissance, attackers engage in large-scale data collection across Microsoft 365 workloads, particularly targeting SharePoint Online and OneDrive for Business. This activity is characterized by high-volume access and download events, often automated to blend in with normal enterprise usage. Microsoft has observed that data exfiltration is typically measured and sustained, allowing attackers to extract sensitive data over extended periods.

Attribution and Recommendations

Microsoft Threat Intelligence attributes these activities to various threat actors, including Storm-3121 and Storm-3032. Organizations are encouraged to implement robust security measures, including phishing-resistant MFA and strict conditional access controls, to mitigate the risks associated with these types of attacks.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Nightspire Ransomware Claims Attack on UAE’s DiamondLease, Demands Negotiations

Nightspire Ransomware Targets UAE's DiamondLease, Demands Negotiations On September 11, 2026, the ransomware group Nightspire publicly claimed responsibility for a cyberattack against DiamondLease, a leading...

Research Reveals Root Access Can Enable Identity Spoofing in SPIFFE/SPIRE on Kubernetes

Executive Summary Recent research from Palo Alto Networks' Unit 42 has unveiled critical vulnerabilities in the Secure...

Pentagon plans to expand tech testing at US-Mexico border with unmanned systems

WASHINGTON — The Pentagon is looking to expand its testing of emerging technologies along the US-Mexico border, focusing on unmanned systems and high-energy lasers....

Meta Faces Lawsuit Over Alleged Unauthorized Use of User Photos for AI and Face Recognition Systems

A group of parents and their children from Illinois and California has filed a lawsuit against Meta in federal court in Chicago, alleging that...