Passkey-themed phishing attacks lead to Microsoft 365 data theft

Corporate Microsoft accounts are under siege as threat actors use sophisticated social engineering tactics to steal data from Microsoft 365 services. These highly targeted attacks, linked to extortion gangs such as ShinyHunters and Helix, rely on convincing employees to update their passkeys or single sign-on configurations via phishing sites designed to mimic legitimate Microsoft login pages.

The attackers conduct extensive research before targeting specific organizations and employees, gathering information from public sources like social networking platforms. They then use this intelligence to craft convincing messages, often via phone calls or messaging apps, posing as corporate IT help desks. The goal is to trick victims into signing in to adversary-in-the-middle (AiTM) phishing sites or using device-code authentication flows.

These tactics allow the attackers to capture sensitive credentials and session tokens, which can be used to access Microsoft 365 services without any further verification. Device code phishing tricks victims into authorizing access to their account via an attacker-controlled client using Microsoft’s legitimate authentication pages. The attackers then use this access to list sensitive files and internal applications, often remaining active in the system for extended periods.

Phishing domains registered by the attackers combine company names with words related to passkeys, single sign-on (SSO), key synchronization, account setup, and identity verification. These domains are designed to appear convincing, with some even incorporating the victim company’s name as a subdomain. For example, a phishing portal might be located at “company-name.secure-passkey.com.”

The attacks have been linked to multiple threat actors operating within the same extortion ecosystem, including groups tracked by Microsoft as Storm-3121 and Storm-3032. These actors are associated with various extortion gangs, including ShinyHunters, Falcon, BlackFile, and Helix. The activity overlaps with previous attacks documented by Google Threat Intelligence under the UNC6671 threat cluster.

Microsoft’s research provides a closer look at what happens inside Microsoft cloud environments after an account is compromised. In one investigated attack, the attacker accessed My Apps to see which applications were assigned to the account, then proceeded to list sensitive files and internal applications within minutes of gaining access. The session remained active for approximately one hour while the attacker continued to explore the compromised account’s permissions.

This latest wave of passkey-themed phishing attacks serves as a stark reminder that even the most advanced security measures can be exploited with clever social engineering tactics. Employees must remain vigilant, especially when receiving unsolicited messages or calls from IT help desks. Companies should also consider implementing additional security measures, such as multi-factor authentication and regular employee training on cybersecurity best practices.

Ultimately, the key to preventing these attacks lies in a combination of robust security measures and employee education. By staying informed about the latest threats and taking proactive steps to protect themselves, individuals can significantly reduce their risk of falling victim to passkey-themed phishing scams.


Source: Bleeping Computer — 2026-09-11