LIVE · cybersecurity feed
Live wire
phishing

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers

zeroday.news ·

Photo: Ank Kumar (CC BY-SA 4.0) via Wikimedia Commons

Microsoft has reported details concerning two distinct campaigns where threat actors leveraged third-party email delivery infrastructure to distribute financial fraud scam messages. These campaigns employed passkey-themed social engineering tactics to compromise cloud environments, ultimately leading to the hijacking of Microsoft cloud accounts and subsequent data exfiltration.

The first campaign, as described by Microsoft, involved the mass distribution of over a million scam emails within a short period, specifically between August 3 and 5, 2026. These emails were designed to impersonate chief executive officers, a common social engineering tactic aimed at inducing urgency and authority to manipulate recipients into performing actions beneficial to the attackers.

The core mechanism of these attacks appears to be passkey phishing. In this type of attack, users are tricked into interacting with malicious prompts or websites that mimic legitimate passkey authentication flows. Instead of authenticating to a legitimate service, victims inadvertently provide their passkey credentials or authorize a malicious passkey registration to the attackers, granting them unauthorized access to their accounts.

Given the focus on Microsoft cloud accounts, the likely targets are organizations and individuals utilizing Microsoft 365, Azure, or other Microsoft cloud services. The exfiltration of data suggests that once account access is gained, attackers move to steal sensitive information, which could range from financial data and intellectual property to personal identifiable information, depending on the compromised environment.

Mitigation for passkey phishing, and phishing in general, typically involves a multi-layered approach. User education is paramount, teaching individuals to recognize phishing attempts, verify sender identities, and scrutinize URLs before interacting with any authentication prompts. Organizations should also implement strong authentication policies, such as requiring hardware security keys for passkey registrations where possible, and continuously monitor for suspicious login activities or unusual data access patterns.

This incident underscores the evolving landscape of phishing attacks, with threat actors adapting to newer authentication methods like passkeys. While passkeys offer enhanced security over traditional passwords by being phishing-resistant in their ideal implementation, the human element remains a critical vulnerability. Attackers continue to innovate social engineering techniques to bypass even advanced security measures, highlighting the ongoing need for robust security awareness training and comprehensive defense-in-depth strategies.

phishingbreachcloudfinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s