Microsoft has reported details concerning two distinct campaigns where threat actors leveraged third-party email delivery infrastructure to distribute financial fraud scam messages. These campaigns employed passkey-themed social engineering tactics to compromise cloud environments, ultimately leading to the hijacking of Microsoft cloud accounts and subsequent data exfiltration.
The first campaign, as described by Microsoft, involved the mass distribution of over a million scam emails within a short period, specifically between August 3 and 5, 2026. These emails were designed to impersonate chief executive officers, a common social engineering tactic aimed at inducing urgency and authority to manipulate recipients into performing actions beneficial to the attackers.
The core mechanism of these attacks appears to be passkey phishing. In this type of attack, users are tricked into interacting with malicious prompts or websites that mimic legitimate passkey authentication flows. Instead of authenticating to a legitimate service, victims inadvertently provide their passkey credentials or authorize a malicious passkey registration to the attackers, granting them unauthorized access to their accounts.
Given the focus on Microsoft cloud accounts, the likely targets are organizations and individuals utilizing Microsoft 365, Azure, or other Microsoft cloud services. The exfiltration of data suggests that once account access is gained, attackers move to steal sensitive information, which could range from financial data and intellectual property to personal identifiable information, depending on the compromised environment.
Mitigation for passkey phishing, and phishing in general, typically involves a multi-layered approach. User education is paramount, teaching individuals to recognize phishing attempts, verify sender identities, and scrutinize URLs before interacting with any authentication prompts. Organizations should also implement strong authentication policies, such as requiring hardware security keys for passkey registrations where possible, and continuously monitor for suspicious login activities or unusual data access patterns.
This incident underscores the evolving landscape of phishing attacks, with threat actors adapting to newer authentication methods like passkeys. While passkeys offer enhanced security over traditional passwords by being phishing-resistant in their ideal implementation, the human element remains a critical vulnerability. Attackers continue to innovate social engineering techniques to bypass even advanced security measures, highlighting the ongoing need for robust security awareness training and comprehensive defense-in-depth strategies.






