Passkey Phishing Attacks Target Microsoft Cloud Accounts, Enable Data Exfiltration
Attackers are using AI-generated phishing emails and passkey-themed social engineering to compromise Microsoft Cloud accounts, enabling data exfiltration and bypassing MFA protections. The campaigns involve spoofed domains, fabricated invoices, and compromised credentials to gain unauthorized access to enterprise cloud environments.
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments.
The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers
*** END OF TRANSMISSION ***