Microsoft Security Research is tracking active cloud-based intrusions that have led to identity and cloud compromises. These attacks typically begin with unusual sign-ins followed by the addition of authentication methods by threat actors, high-volume activity on Microsoft Graph, and extensive downloads from SharePoint and OneDrive. The activity has been observed since May 2026 and is characterized by automated collection from compromised cloud identities using proxy-associated infrastructure. Organizations are advised to investigate this sequence across identity, Microsoft Graph, SharePoint, OneDrive, and Exchange signals, and to revoke sessions and remove unauthorized authentication methods for confirmed compromises. For more details, refer to the Microsoft Threat Intelligence Blog.
Attack Chain Overview
The attack chain begins with identity-focused social engineering, where attackers impersonate IT helpdesk personnel to create a sense of urgency regarding passkey or multifactor authentication (MFA) updates. Victims are directed to phishing sites that resemble legitimate Microsoft sign-in pages. This initial interaction often leaves little forensic evidence, complicating investigations.
Initial Access and User Identity Compromise
Attackers often utilize adversary-in-the-middle (AiTM) phishing techniques to capture credentials and session tokens. In some cases, they may also use device code phishing to gain unauthorized access. Once inside, they can access identity portals and management applications, leading to broader application access and potential data exfiltration.
High-Volume Data Collection and Exfiltration
Following reconnaissance, attackers engage in large-scale data collection across Microsoft 365 workloads, particularly targeting SharePoint Online and OneDrive for Business. This activity is characterized by high-volume access and download events, often automated to blend in with normal enterprise usage. Microsoft has observed that data exfiltration is typically measured and sustained, allowing attackers to extract sensitive data over extended periods.
Attribution and Recommendations
Microsoft Threat Intelligence attributes these activities to various threat actors, including Storm-3121 and Storm-3032. Organizations are encouraged to implement robust security measures, including phishing-resistant MFA and strict conditional access controls, to mitigate the risks associated with these types of attacks.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.



