Security Researchers: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers

The landscape of enterprise cybersecurity is facing a sophisticated and deceptive evolution as threat actors increasingly pivot toward psychological manipulation rather than brute-force technical vulnerabilities. According to recent intelligence published by Microsoft Security Research, a coordinated and ongoing social engineering campaign has been actively exploiting corporate environments since May 2026. This malicious activity relies on passkey-themed phishing schemes, tricking enterprise employees into inadvertently granting attackers access to their cloud identities. Rather than attempting to break through robust cryptographic protocols, these malicious actors are weaponizing the very tools meant to secure modern organizations—namely, passkeys and multi-factor authentication (MFA)—by impersonating trusted internal IT personnel.

The implications of this campaign extend far beyond simple credential theft. Once an initial foothold is secured within a corporate cloud tenant, attackers engage in rapid reconnaissance, privilege escalation, and data exfiltration. The sophisticated nature of these attacks highlights a critical gap in human-centric security, demonstrating that even advanced authentication paradigms can be undermined when users are manipulated through social engineering tactics that mimic routine administrative procedures.

Anatomy of a Social Engineering Campaign

The methodology employed by these threat actors is designed to appear entirely authentic to the unsuspecting corporate employee. The attack sequence typically begins off-network, with the victim receiving a phone call, SMS message, or an internal communication via collaboration platforms such as Microsoft Teams. In many cases, the message originates from a previously compromised employee account within the same organization, lending a false sense of legitimacy to the interaction.

The individual on the other end of the communication poses as a representative from the organization’s IT help desk or security operations center. The imposter informs the employee that an urgent update is required for their passkey setup, multi-factor authentication profile, or single sign-on (SSO) configuration. The victim is told that completing this update immediately is mandatory to prevent service disruption, account lockout, or compliance violations.

Security Researchers: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers -- THE Journal

To facilitate this, the victim is directed to a lookalike web domain meticulously designed to replicate legitimate enterprise sign-in portals, such as Microsoft’s authentication page. Despite the passkey theme of the pretext, security researchers emphasize that forcing the direct creation or theft of a true FIDO2 passkey is rarely the attacker’s primary objective. Instead, the passkey narrative serves as a psychological hook to lure the target into adversary-in-the-middle (AiTM) phishing architectures or device-code authentication flows.

In an AiTM scenario, the malicious proxy sits between the user and the genuine authentication server, capturing primary credentials alongside active session tokens. Alternatively, device-code phishing tricks the user into authorizing access for an external, attacker-controlled client by entering a short code displayed on the fraudulent interface. Once this authorization is granted, the attacker bypasses standard MFA challenges entirely, acquiring a valid session token that grants unfettered access to the user’s cloud environment.

Chronology and Operational Phases

Security telemetry indicates that this campaign has been active across multiple enterprise environments since May 2026. The lifecycle of a typical breach observed during this period follows a structured, multi-phase progression designed to maximize persistence and intelligence gathering before detection occurs.

Phase 1: Initial Access and Discovery
The attack commences with the social engineering pretext, leading to successful authentication from an unmanaged, attacker-controlled device. Once inside the perimeter, the threat actor immediately pivots to identity and application management services. Rather than deploying ransomware or destructive payloads immediately, the intruders focus on reconnaissance. Utilizing Microsoft Graph APIs, the attackers systematically map user accounts, security groups, permission structures, internal applications, and accessible cloud content across the entire corporate tenant.

Phase 2: Establishing Persistence
Recognizing that initial session tokens have a limited lifespan, attackers waste no time securing long-term access. Microsoft’s telemetry reveals that threat actors frequently register new authentication methods under their direct control. These include secondary phone numbers, rogue authenticator applications, and software-based one-time password (OTP) tokens. By embedding these alternate recovery and sign-in mechanisms into the compromised profile, the intruders ensure they can maintain persistent access even if the original user resets their password or if the initial phishing vector is discovered.

Security Researchers: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers -- THE Journal

Phase 3: Lateral Movement and Data Exfiltration
With persistence established, the attackers leverage cloud-native tools to locate and harvest high-value data. SharePoint Online and OneDrive are primary targets, where scripts execute automated file enumeration to locate sensitive internal documents, intellectual property, financial records, and executive communications. Simultaneously, attackers access corporate mailboxes via REST APIs, collecting email threads and attachments. In many observed instances, these unauthorized sessions persist for roughly an hour—a window long enough to execute targeted exfiltration without triggering immediate behavioral anomalies in traditional security information and event management (SIEM) systems.

Attribution and Threat Actor Profiles

Microsoft has attributed the initial access activities tied to this specific campaign to multiple distinct threat actor groups, highlighting a collaborative or shared-services model within the cybercriminal ecosystem. Specifically, researchers have linked portions of the campaign to clusters designated as Storm-3121 and Storm-3032.

Storm-3121 is primarily recognized for conducting initial access operations that frequently precede high-impact extortion campaigns, including those associated with ransomware syndicates like ShinyHunters and Falcon. These actors specialize in breaching corporate perimeters and selling or leveraging access for subsequent financial extortion.

Meanwhile, Storm-3032 comprises operators who previously split from the notorious BlackFile ransomware group and now operate under the Helix extortion banner. The involvement of these experienced threat actor profiles underscores the seriousness of the campaign; what begins as a targeted phishing call often culminates in enterprise-wide data theft and extortion demands.

Implications for Enterprise Security

Security Researchers: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers -- THE Journal

The rise of passkey-themed social engineering represents a psychological shift in cyber attacks. For years, the cybersecurity community has championed passkeys and FIDO2-compliant hardware tokens as the ultimate antidote to credential theft, citing their resistance to traditional phishing techniques. While the cryptographic integrity of passkeys remains sound, this campaign demonstrates that the human element remains the weakest link in the security chain.

Attackers are not breaking the technology; rather, they are exploiting user trust in internal IT support structures. When an employee believes they are speaking with their own help desk, standard technological safeguards can be bypassed because the user willingly authorizes the connection. This dynamic poses profound implications for Chief Information Security Officers (CISOs) and IT administrators. Traditional security awareness training that focuses exclusively on spotting poorly spelled phishing emails or suspicious links is no longer sufficient when threat actors utilize personalized phone calls, compromised internal team channels, and convincing conversational pretexts.

Furthermore, the heavy reliance on legitimate administrative tools—such as Microsoft Graph APIs, SharePoint, OneDrive, and legitimate device-code flows—means that malicious activity often blends seamlessly with normal business operations. This "Living off the Cloud" technique allows attackers to operate beneath the radar of signature-based detection tools, making behavioral analysis and zero-trust architecture essential components of modern defense strategies.

Recommended Mitigation and Remediation Strategies

In response to the proliferation of these identity-based cloud compromises, Microsoft and independent cybersecurity experts have issued comprehensive hardening guidelines for enterprise environments. Organizations are strongly advised to implement a multi-layered defense strategy that addresses both technical controls and organizational culture.

  1. Enforce Phishing-Resistant MFA: Organizations should mandate the use of true phishing-resistant multi-factor authentication, such as FIDO2 passkeys and Windows Hello for Business, enforced strictly through Azure AD or Entra ID Conditional Access policies. Crucially, policies must be configured to disallow legacy authentication methods that can be intercepted via adversary-in-the-middle proxies.

    Security Researchers: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers -- THE Journal
  2. Restrict Device-Code Flows: Because device-code authentication is frequently abused in social engineering attacks to authorize unmanaged external clients, administrators should evaluate whether this feature is required for standard users. Where unnecessary, device-code and authentication-transfer flows should be systematically blocked or restricted exclusively to administrative accounts and managed devices.

  3. Enhance Behavioral Monitoring: Security teams must update their monitoring rules to detect anomalous patterns indicative of this campaign. Key indicators include unusual sign-ins originating from unmanaged devices immediately followed by the registration of new authentication methods (such as external phone numbers or third-party authenticator apps). Additionally, defenders should monitor for high-volume Microsoft Graph activity, atypical SharePoint and OneDrive enumeration, and unusual mailbox access via REST APIs.

  4. Strengthen Help Desk Verification Protocols: To combat IT impersonation scams, enterprises must establish out-of-band verification procedures for IT support requests. Employees should be trained to verify the identity of help desk personnel through internal ticketing systems or secondary communication channels before making any modifications to their account security settings or authentication profiles.

Conclusion

The passkey-themed social engineering campaign observed since May 2026 serves as a sobering reminder that cyber adversaries continually adapt their tactics to circumvent technological advancements. By weaponizing human trust and manipulating the rollout of advanced authentication standards, threat actors have found a viable pathway to enterprise cloud takeovers. As organizations continue their digital transformation journeys and adopt next-generation security paradigms, securing the human element through robust verification practices, strict conditional access policies, and vigilant behavioral monitoring will remain paramount in safeguarding enterprise identities and sensitive cloud assets.

Leave a Reply

Your email address will not be published. Required fields are marked *