Passkey-themed phishing attacks lead to Microsoft 365 data theft
AI Generated Image

Passkey-themed phishing attacks lead to Microsoft 365 data theft

BleepingComputer technology

Key Points:

  • Since May 2026, threat actors linked to extortion gangs such as ShinyHunters and Helix have used passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft 365 accounts by impersonating IT help desks and directing victims to phishing sites.
  • Attackers employ adversary-in-the-middle (AiTM) phishing and device-code authentication flows to capture credentials and session tokens, enabling access to a wide range of Microsoft 365 and connected third-party services without triggering additional MFA challenges.
  • After compromise, attackers conduct extensive reconnaissance using Microsoft Graph API to enumerate organizational data, users, roles, and cloud resources before systematically exfiltrating files from SharePoint Online, OneDrive, and Exchange Online over extended periods to avoid detection.
  • Microsoft attributes these attacks to multiple threat groups within the same extortion ecosystem, including Storm-3121 (ShinyHunters/Falcon) and Storm-3032 (Helix/BlackFile), with overlapping activity previously documented by Google under UNC6671.
  • To mitigate risks, Microsoft advises monitoring for unusual sign-ins, new MFA registrations, and suspicious Microsoft Graph activity; revoking compromised sessions; enforcing phishing-resistant MFA; limiting sensitive resource access to managed devices; and disabling device-code authentication when unnecessary.

Trending Business

Trending Technology

Trending Health