Passkey-themed phishing attacks lead to Microsoft 365 data theft

September 12, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: bleepingcomputer.com

Threat Risk: High
Victim: Corporate Microsoft 365 users
Incident: A coordinated phishing campaign using passkey-themed lures to hijack Microsoft 365 sessions.
Impact: Unauthorized access to enterprise cloud environments leading to corporate data theft.
Attacker: Storm-3121, Storm-3032, and UNC6671 (linked to ShinyHunters and Helix)
Analysis: Threat actors are leveraging sophisticated social engineering and Adversary-in-the-Middle (AiTM) techniques to bypass traditional MFA. By impersonating IT help desks and using ‘passkey update’ lures, they redirect victims to deceptive portals to capture session tokens. This allows attackers to gain full access to corporate environments without needing the user’s actual password.
Recommendations: Implement phishing-resistant MFA such as FIDO2 or WebAuthn; Disable device-code authentication if not strictly required for business operations; Restrict access to sensitive cloud resources to company-managed devices
Source: BleepingComputer

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *