Security Researchers: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers

Cybersecurity researchers have uncovered a sophisticated and active social engineering campaign leveraging the growing corporate adoption of passkeys to infiltrate enterprise cloud environments. Threat actors are impersonating internal IT help desks, convincing corporate employees to engage in fraudulent passkey configuration workflows, and subsequently hijacking their digital identities. According to telemetry and analysis released by Microsoft Security Research, these attacks have been observed since May 2026, targeting multiple organizations and resulting in widespread enterprise cloud data compromises, unauthorized file exfiltration, and persistent access to cloud-based tenant infrastructure.

The methodology behind these attacks demonstrates a sharp pivot in cybercriminal tactics. While passkeys and FIDO2-compliant security credentials are widely lauded by security architects as the gold standard for phishing resistance, malicious actors are circumventing the technology not by cracking cryptography, but by exploiting human trust. By manipulating employees into believing that an urgent security update or single sign-on (SSO) maintenance procedure is necessary to prevent network disruption, attackers pave the way for high-impact session hijacking.

Anatomy of a Passkey-Themed Social Engineering Campaign

The attack lifecycle typically begins away from the corporate network, utilizing direct communication channels targeting an employee’s personal phone number or messaging application. Posing as trusted members of the corporate IT help desk or security operations center, the threat actors fabricate an urgent narrative. They inform the unsuspecting victim that their multifactor authentication (MFA) profile, enterprise passkey, or SSO configuration requires an immediate update or re-enrollment to maintain system access or prevent operational downtime.

Security Researchers: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers -- THE Journal

Once the employee is hooked, the scammers direct them to meticulously crafted phishing websites engineered to replicate legitimate corporate sign-in portals—frequently mimicking Microsoft identity management pages. In more advanced instances, threat actors leverage already compromised corporate accounts to distribute malicious links via SMS or internal collaboration tools like Microsoft Teams. This internal messaging vector adds a dangerous layer of legitimacy, as targets believe they are communicating with verified colleagues.

Despite the passkey-themed framing of the social engineering script, Microsoft’s investigation reveals that enrolling a legitimate passkey is rarely the attacker’s true technical goal. Instead, the pretext is merely a vehicle to funnel victims through adversary-in-the-middle (AiTM) phishing frameworks or device-code authentication flows. In an AiTM attack, proxy servers intercept traffic between the user and the legitimate identity provider, harvesting primary credentials in real-time alongside session cookies and authentication tokens. Meanwhile, device-code phishing tricks the victim into visiting an authorization URL and inputting a specific code, inadvertently granting an attacker-controlled client application full access to their corporate account.

Exploitation, Reconnaissance, and Persistence

Once initial access is established, threat actors waste little time expanding their footprint within the compromised cloud ecosystem. Microsoft’s security analysts have documented a distinct chain of post-compromise behavior. Typically initiated from unmanaged, external devices, the unauthorized sign-in is quickly followed by direct interaction with identity and application management services.

During incidents analyzed by Microsoft, threat actors heavily abused Microsoft Graph—a unified API endpoint designed to facilitate data access across Microsoft 365 services. Attackers leveraged Microsoft Graph and direct protocols to comprehensively enumerate sensitive corporate documents stored in SharePoint Online and OneDrive. In many cases, active session persistence lasted roughly an hour, during which time malicious actors executed high-volume searches for internal applications, proprietary files, financial spreadsheets, and confidential corporate communications.

Security Researchers: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers -- THE Journal

Crucially, the initial intrusion is rarely treated as a one-off event. To secure long-term access and insulate themselves against standard remediation efforts, attackers immediately register new, malicious authentication methods under their administrative control. These methods include enrolling attacker-controlled phone numbers, configuring unauthorized authenticator applications, and registering software-based one-time password (OTP) tokens. By establishing these secondary fallback mechanisms, the threat actors ensure they can successfully satisfy future authentication challenges, effectively transforming a momentary lapse in judgment into a persistent, deeply embedded foothold within the enterprise tenant.

Following authentication modification, the scope of the reconnaissance expands. Threat actors utilize Microsoft Graph to meticulously map user directories, security groups, individual permissions, connected applications, and accessible content repositories across the enterprise tenant. Over time, this reconnaissance paves the way for deeper lateral movement, enabling the exfiltration of sensitive emails, file attachments, and internal document libraries.

Attribution and Threat Actor Profiles

Microsoft Security Research has attributed the initial access phases of this ongoing campaign to distinct, highly active cybercriminal syndicates, specifically identifying threat clusters designated as Storm-3121 and Storm-3032.

Storm-3121 is well-known within the threat intelligence community for specializing in initial access brokerage and large-scale credential harvesting. Historically, operational activity originating from Storm-3121 has frequently transitioned downstream into destructive extortion campaigns, including those orchestrated by the notorious ShinyHunters and Falcon extortion gangs.

Security Researchers: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers -- THE Journal

Similarly, Storm-3032 represents an offshoot of experienced cybercriminals who previously operated under the BlackFile ransomware banner before rebranding and pivoting their operational focus under the Helix extortion umbrella. The involvement of these established criminal groups underscores the high financial stakes of the campaign, indicating that stolen corporate identities are systematically monetized through data theft, corporate espionage, and extortion demands.

Broader Implications for Enterprise Security

The emergence of passkey-themed social engineering campaigns highlights a critical paradox in modern enterprise security: while technological defenses are evolving to become mathematically robust, human vulnerability remains the path of least resistance. Organizations pouring resources into modern authentication architectures must recognize that bad actors are adapting their social engineering playbooks to match the technological landscape.

When employees are told that a new technology is mandatory for their day-to-day work, they readily comply with instructions given by perceived authority figures. Attackers weaponize this compliance, bypassing cryptographic defenses by tricking the user into handing over session tokens or authorizing rogue devices directly. This trend signals that user education must evolve past generic phishing awareness to specifically address emerging authentication concepts, such as passkey enrollment procedures, device-code authentication prompts, and out-of-band verification requests.

Defensive Recommendations and Mitigation Strategies

Security Researchers: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers -- THE Journal

In response to the rising frequency of these cloud account takeovers, Microsoft and independent cybersecurity experts have outlined comprehensive hardening strategies for enterprise security administrators. Chief among these recommendations is the strict enforcement of phishing-resistant multifactor authentication. Organizations should mandate hardware-backed FIDO2 passkeys or Windows Hello for Business, ensuring that these credentials are deployed and managed strictly through centralized Mobile Device Management (MDM) or Conditional Access policies rather than ad-hoc user enrollments.

Furthermore, security teams should audit and restrict authentication flows that are frequently abused by threat actors. Specifically, administrators should consider blocking device-code authentication and risky token-transfer flows across the enterprise where business requirements do not explicitly demand them.

From a monitoring perspective, Security Operations Centers (SOCs) must establish robust detection rules to flag anomalous behavioral patterns. Investigations should be immediately triggered whenever an unusual sign-in from an unmanaged device is quickly followed by the registration of a new authentication method, high-volume Microsoft Graph reconnaissance, or abnormal access spikes across SharePoint, OneDrive, and corporate mailboxes. By combining hardened technical controls with vigilant behavioral monitoring, organizations can disrupt these sophisticated identity attacks before threat actors can secure a permanent foothold in the cloud.

Leave a Reply

Your email address will not be published. Required fields are marked *