Passkey Phishing Targets Microsoft Cloud Accounts
Attackers are exploiting passkey authentication themes in phishing campaigns to compromise Microsoft cloud environments. Over a million fraudulent emails were sent伪装 as CEO communications to initiate financial scams.
TL;DR
- Microsoft uncovered two phishing campaigns using passkey-themed social engineering.
- Over 1 million scam emails sent in early August 2026伪装 as CEO messages.
- Attackers targeted Microsoft cloud accounts to exfiltrate sensitive data.
- Campaigns abused third-party email infrastructure for delivery.
- Organizations should警惕 new passkey-related social engineering tactics.
Cybercriminals are evolving their phishing strategies by leveraging the growing adoption of passkey authentication. In newly disclosed campaigns, attackers have used social engineering centered around passkey themes to infiltrate Microsoft cloud environments.
Between August 3 and 5, 2026, threat actors sent more than a million fraudulent emails disguised as internal CEO communications. These messages aimed to trick recipients into engaging with malicious content that could lead to account takeover and data exfiltration.
Phishing Technique Breakdown
- Attackers used passkey-themed lures to appear legitimate during authentication workflows.
- Emails伪装 as urgent CEO requests to increase click-through rates.
- Third-party email delivery services were compromised to distribute spam at scale.
- Messages contained links or attachments designed to harvest credentials or session tokens.
Impact on Cloud Security
- Successful compromises led to unauthorized access to Microsoft cloud resources.
- Data exfiltration was observed following initial account takeovers.
- Multi-factor authentication bypass attempts included abuse of passkey registration flows.
- Organizations using default security settings faced higher risk of credential theft.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.