Skip to article
Decision intelligence for people who build, buy, and govern technology.How this desk reports

Enterprise IT

News update

Attackers Use Passkey Phishing to Breach Enterprise Accounts

Microsoft exposes cyber campaigns using passkey phishing lures and fake IT help desks to hijack corporate cloud accounts and exfiltrate sensitive data.

Key takeaways

    • Targeted Identity Pretexts: Adversaries contact employees on personal phone numbers impersonating internal IT staff, weaponizing urgency around passkey and SSO upgrades to drive credential theft.
    • AiTM and Device-Code Exploitation: Threat actors route victims through proxy-based adversary-in-the-middle or device code authentication flows, bypassing traditional MFA prompts without triggering standard user warnings.
    • Rogue MFA Registration: Attackers immediately register their own authenticators or phone numbers to convert temporary session theft into unassisted, long-term persistence across cloud tenants.
    • Microsoft Graph Exfiltration: Intruders leverage REST APIs and Graph endpoints to automate reconnaissance and execute sustained data theft across SharePoint Online, OneDrive, and Exchange mailboxes.

Threat actors are exploiting enterprise transitions toward passwordless authentication by deploying passkey-themed phishing lures, voice phishing (vishing), and fake IT help desks to compromise corporate Microsoft cloud environments. According to Microsoft threat intelligence, cybercrime groups including Storm-3032 (UNC6671) and Storm-3121 target employees on personal devices, guiding them through adversary-in-the-middle (AiTM) or device-code authentication flows. Once initial access is obtained, attackers register their own multi-factor authentication (MFA) methods to establish persistence, abuse Microsoft Graph APIs to map tenant permissions, and systematically exfiltrate sensitive files from SharePoint Online and OneDrive for Business. Simultaneously, operators have launched massive generative-AI-crafted invoice fraud campaigns, highlighting severe identity risks for corporate administrators.

Help Desk Impersonation and Adversary-in-the-Middle Tactics

As enterprises accelerate adoption of FIDO2 tokens and passkeys to strengthen access controls, threat actors have adapted their social engineering playbooks to manipulate these exact security initiatives. Security research published by Microsoft Security Research details how intrusions detected since May 2026 begin with identity-centric pretexts directed at employees’ personal smartphones. Operators conduct extensive open-source intelligence on corporate hierarchies via professional networking platforms, identifying specific staff and their departmental roles.

Attackers then initiate voice calls or SMS messages posing as corporate IT help desk personnel. The caller warns the employee that immediate updates to their passkey, single sign-on (SSO), or MFA configuration are required to avert imminent service disruption. SMS links redirect targets to sophisticated phishing portals that clone legitimate Microsoft authentication interfaces. These portals are hosted on thematic root domains—such as passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, and portalsetuphub[.]com—with the victim organization’s brand prepended as a subdomain.

During the interaction, the threat actor proxies the victim’s session using adversary-in-the-middle frameworks or prompts the user through an OAuth device-code authorization flow. In device-code scenarios, the victim enters an authentication code on a counterfeit portal, unknowingly authorizing the attacker’s remote session directly without disclosing cleartext passwords or session cookies to the victim’s local browser cache. In secondary scenarios, attackers who have already compromised an account leverage Microsoft Teams to message colleagues internally with identical passkey enrollment pretexts.

MFA Persistence and Automated Microsoft Graph Exfiltration

Once initial entry is achieved, the threat actor’s primary operational goal is converting transient access into an unassisted, persistent foothold. Rather than maintaining active interactive sessions that could be invalidated by password resets or administrative revoking of tokens, the intruders immediately enroll their own authentication methods within the victim’s corporate identity profile. Documented methods include registering secondary phone numbers for SMS verification, attacker-controlled authenticator applications, and software-based one-time password (OTP) tokens.

With an independent second factor established, the adversary can sign in at will from unmanaged endpoints without requiring further user cooperation. Microsoft’s incident analysis revealed that actors executed anomalous sign-ins to Microsoft Office Home from unmanaged devices, subsequently leveraging the Microsoft Graph API and associated REST interfaces to conduct broad reconnaissance across the tenant. This activity inventories organizational directories, security groups, assigned administrative privileges, and high-value service principals.

Intelligence gathering rapidly transitions into high-volume, programmatic data harvesting. Compromised cloud identities are used to query SharePoint Online, OneDrive for Business, and Microsoft Exchange Online. Intruders systematically exfiltrate sensitive internal documentation, confidential mailboxes, and folder metadata. Depending on tenant volume, exfiltration phases persist from several hours to multiple consecutive days. To circumvent IP-reputation alerts and network anomaly detections, the operators deliberately route traffic through residential proxies and rotate infrastructure dynamically between authentication, enumeration, and exfiltration stages.

Generative AI Invoice Fraud and Cross-Campaign Activity

Attackers Use Passkey Phishing to Breach Enterprise Accounts: Generative AI Invoice Fraud and Cross-Campaign Activity
Supporting visual for Generative AI Invoice Fraud and Cross-Campaign Activity.

The identity intrusions coincide with a separate, massive financial deception campaign disclosed by Microsoft that underscores the growing intersection of automated email infrastructure abuse and corporate impersonation. Between August 3 and August 5, 2026, threat actors sent more than one million spoofed emails targeting accounts payable teams across U.S. enterprises in manufacturing, consumer goods, real estate, and IT services.

Get the Weekly Brief

Curated analysis for tech leaders. Every Thursday.

Subscribe

The campaign leveraged third-party email delivery services and spoofed domains such as service-nowinc[.]com and domainlify[.]net. By utilizing generative artificial intelligence to craft polished, recipient-specific correspondence, the attackers fabricated legitimate-looking invoice chains for fictitious annual ServiceNow subscriptions. Emails incorporated the actual names and corporate email addresses of target CEOs, CFOs, and presidents into signature blocks alongside forged internal approval threads, directing finance staff to execute urgent Automated Clearing House (ACH) transfers to attacker-controlled bank accounts.

Comparison of Active Cloud Identity and Financial Fraud Campaigns
Campaign Dimension Passkey Social Engineering & Cloud Theft Executive Invoice & ACH Wire Fraud
Observed Timeline Active since May 2026 Over 1 million messages sent August 3–5, 2026
Attributed Adversaries Storm-3032 (UNC6671 / Helix), Storm-3121 Unspecified financial cybercrime operators
Initial Access Vector Vishing and SMS lures to personal mobile phones Spoofed email blasts via third-party infrastructure
Exploitation Technique AiTM phishing, device-code flows, rogue MFA enrollment Generative AI email drafting, executive impersonation
Primary Objective Graph API enumeration, OneDrive/SharePoint exfiltration Direct financial diversion via fraudulent ACH payments
Targeted Roles Enterprise workforce and privileged cloud users Accounts payable and enterprise finance personnel

The cloud intrusion clusters overlap with a wider syndicate tracked across the security industry as Cordial Spider, O-UNC-045, PREY-0058, and UNC6671. Cybersecurity telemetry documented by UNC6671 extortion tracking highlights that splinter groups have operated under multiple extortion banners, including Redact, Pink, Helix, and Falcon, netting more than $10.6 million in cryptocurrency ransom payments between January and May 2026. Microsoft attributes the initial access and extortion branches to Storm-3032 and Storm-3121, who routinely share commoditized phishing kits and credential harvesting portals.

What happens next

Enterprise identity architectures face a sophisticated operational challenge: individual Microsoft Graph API requests appear identical to legitimate administrative or productivity workflows. Security operations centers cannot rely on static alert rules triggered by isolated API calls. Defending against these intrusion chains requires cross-event correlation that links anomalous device sign-ins, immediate MFA registration events, and sudden spikes in Graph API data extraction.

In response, IT directors and cloud architects must tighten identity onboarding and credential recovery policies. While organizations evaluate Microsoft enterprise security updates, administrative controls should immediately restrict self-service MFA enrollment and device registration to compliant, Intune-managed devices or trusted internal networks. Conditional Access policies must be configured to disallow device-code flow authorization for standard user profiles unless explicitly mandated by specific headless workloads.

Furthermore, enterprise security training must evolve beyond traditional email phishing drills. Help desk teams require strict out-of-band verification procedures before guiding employees through credential recovery, while end-users must be educated that corporate IT departments will never direct employees via SMS to external identity domains to configure passkeys. As threat groups continue commoditizing voice phishing kits and AI-generated lures, organizations maintaining hybrid SaaS environments must treat identity configuration changes as Tier-0 security events.

Sources

Accountable publisher

TechNodeHQ Editorial Desk

Automated research and drafting with accountable publishing controls, transparent sourcing, and a public correction route.

Signal Briefing

Important technology changes, with the decision attached.

A concise briefing product is being finalized. No invented cadence or subscriber claim.

Ask about the briefing