Passkey-themed phishing attacks lead to Microsoft 365 data theft

A wave of targeted phishing attacks has been compromising corporate Microsoft accounts, allowing threat actors to steal data from Microsoft 365 services. The attackers, linked to extortion gangs such as ShinyHunters and Helix, have been using social engineering tactics to trick employees into updating their passkeys or single sign-on (SSO) configurations, often through fake IT help desk calls or messages.

The phishing attacks begin with the attackers researching targeted organizations and employees before making contact. They pose as corporate IT help desks, warning employees that urgent action is needed to update a passkey, multi-factor authentication (MFA), or SSO configuration, lest they lose access to their company systems. The victims are then directed to phishing sites designed to resemble legitimate Microsoft login pages, often via links sent through SMS messages to their personal phones.

While the attackers frequently use passkey-themed lures, these are not attempts to enroll a passkey. Instead, the goal is to trick employees into signing in to adversary-in-the-middle (AiTM) phishing sites or using device-code authentication flows, which allow the attackers to capture credentials and session tokens. In some cases, the victims are directed to enter a provided code into Microsoft’s legitimate authentication pages.

The attackers appear to invest significant time in researching their targets before launching an attack. They gather information about employees and organizational structure from public sources such as social networking and professional profiling platforms. To make the phishing portals more convincing, they register domains that combine company names with words related to passkeys, SSO, key synchronization, account setup, and identity verification.

Microsoft has identified multiple threat actors operating in this extortion ecosystem, including groups it tracks as Storm-3121 and Storm-3032. These groups are associated with ShinyHunters and Helix extortion gangs, respectively. The activity overlaps with previous attacks documented by Google Threat Intelligence under the UNC6671 threat cluster, which also linked to the same extortion gangs.

Once an account is compromised, Microsoft’s research reveals what happens inside their cloud environments. In one investigated attack, the attacker accessed a valid session after completing MFA and used it to access various resources, including My Apps, My Profile, Microsoft Approval Management, and SharePoint Online. The session remained active for approximately one hour while the attacker listed sensitive files and internal applications.

The passkey social engineering attacks have significant implications for organizations relying on Microsoft 365 services. To mitigate these threats, employees must be vigilant about unsolicited calls or messages from IT help desks, especially those requesting urgent action to update a passkey or SSO configuration. Organizations should also ensure their employees are aware of the proper procedures for updating passkeys and SSO configurations, and that they never enter sensitive information into links sent via SMS or through unknown websites.

As with any targeted phishing attack, prevention is key. Employees must be educated on how to identify and report suspicious activity, and organizations should consider implementing additional security measures such as multi-factor authentication and account monitoring. By being proactive in addressing these threats, organizations can reduce the risk of a successful breach and protect their sensitive data.


Source: Bleeping Computer — 2026-09-11