Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Cyberattackers have been exploiting a weakness in Microsoft’s cloud authentication system, using a technique known as passkey phishing to gain unauthorized access to user accounts and steal sensitive data. The attackers are targeting users of Microsoft Azure Active Directory (Azure AD), which is used by millions of businesses worldwide for identity management and access control.

At its core, the attack relies on social engineering tactics to trick victims into surrendering their account credentials or passkeys. Once compromised, these accounts can be leveraged as a foothold to infiltrate larger networks and exfiltrate sensitive data. The attackers’ primary goal appears to be financial gain, although some experts speculate that they may also be seeking strategic insights or intellectual property.

The attack vector is quite straightforward: attackers send targeted phishing emails to Azure AD administrators, posing as legitimate Microsoft representatives or other trusted parties. These emails contain links or attachments that supposedly facilitate account updates or maintenance procedures. Unsuspecting recipients click on the links or download the attachments, unknowingly entering their passkeys and allowing the attackers to intercept them.

The vulnerability lies in the way Azure AD handles authentication requests from cloud-based applications. When a user attempts to access an application using Azure AD credentials, the system generates a unique authorization token that is transmitted between the client and server. Attackers can hijack these tokens by exploiting weaknesses in the client-side code or through clever social engineering tactics, allowing them to impersonate legitimate users.

The impact of this attack has been significant, with several major organizations confirming they have fallen victim to the scheme. Microsoft has issued a statement acknowledging the issue and providing guidance on how to mitigate it, but some experts warn that this may be just the tip of the iceberg. “This is not an isolated incident,” says one security researcher. “We’re seeing more sophisticated attacks like this all the time – attackers are getting better at exploiting psychological vulnerabilities in addition to technical ones.”

To protect themselves from similar attacks, users should prioritize account security best practices, such as enabling multi-factor authentication (MFA) and regularly monitoring account activity for suspicious behavior. Additionally, administrators should remain vigilant when handling sensitive data and be cautious when interacting with unsolicited emails or attachments – especially those purporting to originate from trusted sources like Microsoft.


Source: The Hacker News — 2026-09-13