Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Summary
Threat actors are leveraging passkey-themed phishing campaigns and third-party email delivery infrastructure to compromise Microsoft cloud accounts. These attacks aim to exfiltrate data and conduct financial fraud, with one campaign sending over a million scam emails in August 2026.
IFF Assessment
This article details sophisticated phishing attacks and account hijacking techniques that pose a significant threat to cloud environments and data security.
Defender Context
Defenders should be aware of evolving phishing tactics that exploit new technologies like passkeys and the misuse of legitimate third-party infrastructure. Implementing robust email filtering, user training on social engineering, and strong multi-factor authentication (MFA) are crucial to mitigating these threats.