LmCast :: Stay tuned in

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Recorded: Sept. 11, 2026, 6 p.m.

Original Summarized

Passkey-themed phishing attacks lead to Microsoft 365 data theft

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Artifactory flaws chained in attacks deploying backdoor malware

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

GitLab urges users to patch max severity path traversal flaw

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityPasskey-themed phishing attacks lead to Microsoft 365 data theft

Passkey-themed phishing attacks lead to Microsoft 365 data theft

By Lawrence Abrams

September 11, 2026
01:26 PM
0

Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.
The activity has been observed since May 2026 and begins with the attackers researching targeted organizations and employees before calling or messaging victims while impersonating corporate IT help desks.
The attackers tell employees that they must urgently update a passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to avoid losing access to corporate systems.
Victims are then directed to phishing sites designed to resemble legitimate Microsoft login pages, with links sometimes sent through SMS messages to employees' personal phones.
Microsoft says that while the lures frequently revolve around passkeys, the attackers are not attempting to enroll a passkey.
Instead, the passkey lures are used to trick targeted employees into signing in to adversary-in-the-middle (AiTM) phishing sites or using device-code authentication flows.
AiTM attacks allow the threat actors to capture credentials and session tokens. Device code phishing tricks victims into authorizing access to their account via an attacker-controlled client using Microsoft's legitimate authentication pages.
Microsoft says the attackers conduct extensive research before targeting employees.
"The actor appears to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms," explains Microsoft.
The threat actors also register phishing domains that combine company names with words related to passkeys, SSO, key synchronization, account setup, and identity verification.
Some examples seen by Microsoft include: passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, oktasession[.]com, keysyncos[.]com, and oskeysync[.]com.
The attackers commonly place the victim company's name in a subdomain, such as company-name.secure-passkey[.]com, to make the phishing portal appear more convincing.
Microsoft attributes the initial-access activity to multiple threat actors operating in the same extortion ecosystem, including groups it tracks as Storm-3121 and Storm-3032.
Storm-3121 is associated with ShinyHunters and Falcon extortion, while Storm-3032 is believed to be tied to BlackFile extortion group members that now work under the Helix name.
This activity overlaps with attacks previously documented by Google Threat Intelligence under the UNC6671 threat cluster.
Google previously reported that UNC6671 uses phone-based social engineering and passkey-themed phishing infrastructure to compromise corporate identities before accessing enterprise cloud environments.
Google has also linked UNC6671 activity to the same extortion gangs, including BlackFile, Helix, Falcon, Pink, and Redact.
Mapping the Microsoft cloud after compromise
Microsoft's new research gives a closer look at what happens inside Microsoft cloud environments after an account is compromised.
In one investigated attack, Microsoft observed a suspicious sign-in from an unmanaged device to a Microsoft 365 service identified in Entra logs as "OfficeHome."
OfficeHome is associated with the Office 365 portal's shared infrastructure, including Office applications accessed through a browser.
After completing MFA, Microsoft says the attacker established a valid session and began checking what resources the compromised account could access.
Within minutes, the session was used to access My Apps to see what applications are assigned to the account, My Profile for organizational information, Microsoft Approval Management, account-management interfaces, and My Sign-Ins.
The attacker then accessed SharePoint Online, Outlook Web, Microsoft 365 collaboration and search services, an internal business application, and authentication flows associated with virtual desktops.
Microsoft says the session remained active for approximately one hour while the attacker listed sensitive files and internal applications.
In another attack, the passkey social engineering attacks led to device-code phishing, where the victim was convinced to enter a supplied code into Microsoft's legitimate authentication page.

Microsoft's device authentication form
This issues an authentication token to the attacker-controlled OAuth application, allowing the threat actor to access the victim's account without completing another MFA challenge.
The attacker now has access to all of the user's resources and connected SSO applications, whether they be Microsoft 365, Salesforce, Google Workspace, Dropbox, Adobe, SAP, Slack, Zendesk, Atlassian, and many others.
In a third attack, the threat actor used previously compromised credentials for an account where it is believed an authenticator application had been registered days earlier.
Microsoft says the threat actors then performed reconnaissance using an automated Node.js system and Microsoft Graph.
After gaining access, the attackers often gain persistence by adding an MFA method they control.
Microsoft says the attackers register new phone numbers, authenticator applications, and software-based one-time password tokens with compromised identities.
This allows the threat actor to satisfy future MFA challenges without the victim's help, although Microsoft notes that the persistence does not survive a complete credential and session reset.
The attackers then use Microsoft Graph to enumerate the victim's cloud environment.
Microsoft saw Graph requests that enumerate:
Organizations, licenses, and enabled services
Users, groups, and group membership
Directory roles and privileged accounts
Registered authentication methods
Applications and service principals
OAuth permissions and application role assignments
SharePoint sites, document libraries, folders, and files
OneDrive resources
Mail folders, messages, and attachments
Microsoft says Graph requests such as /users, /groups, or /sites are common in enterprise environments, so they may not raise alarms.
However, the activity becomes more suspicious when the same account, application, or access token rapidly moves across different resources, checks privileges and authentication settings, and then begins accessing email, attachments, files, or documents.
After reconnaissance, the attackers move into cloud data collection from Microsoft 365.
"Microsoft observed high-volume access and download activity targeting Microsoft SharePoint Online and Microsoft OneDrive for Business, with some intrusions extending into Microsoft Exchange Online through REST API-based access to email content," explained Microsoft.
"Across SharePoint and OneDrive, the activity generated significant volumes of FileAccessed and FileDownloaded events, indicating systematic retrieval of cloud-hosted documents and organizational data."
Microsoft says the activity appears automated, with connections using the python-httpx user agent during SharePoint and OneDrive access exfiltration.
The attackers also appear to avoid rapid "smash-and-grab" exfiltration to avoid detection.
Microsoft says the data theft instead lasts from a few hours to multiple days, with threat actors accessing fewer than 1,000 files or emails in a single hour to blend in with legitimate traffic.
Microsoft recommends looking for unusual sign-ins followed by new MFA registrations, Microsoft Graph reconnaissance, and suspicious access to SharePoint, OneDrive, or Exchange.
If an account is compromised, administrators should revoke active sessions and tokens, reset credentials, remove any authentication methods or mailbox rules added by the attackers, and require the user to re-register their authentication methods.
Microsoft also recommends using phishing-resistant MFA, limiting sensitive cloud resources to managed devices, and disabling device-code authentication when it is not needed.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion groupMan gets six years for hacking 750 women's Snapchat accountsShinyHunters hackers claim breach of Florida "DAVID" DMV databaseNovocure data breach affects more than 1,400 cancer patientsReliaQuest confirms failed data-theft attack after ShinyHunters breach

Data Theft
Device Code
Extortion
Falcon
Helix
Phishing
ShinyHunters
Social Engineering
Vishing

Lawrence Abrams
Lawrence Abrams is the owner and Editor in Chief of BleepingComputer.com. Lawrence's area of expertise includes Windows, malware removal, and computer forensics. Lawrence Abrams is a co-author of the Winternals Defragmentation, Recovery, and Administration Field Guide and the technical editor for Rootkits for Dummies.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

September Windows Server updates break Remote Desktop Services

Microsoft Excel KB5002914 update breaks copy and paste for some users

Sponsor Posts

Overdue a password health-check? Audit your Active Directory for free

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Passkey-themed phishing attacks are being utilized by threat actors, linked to extortion gangs such as ShinyHunters and Helix, to compromise corporate Microsoft accounts and exfiltrate data from Microsoft 365 services. These attacks commence with attackers conducting extensive pre-attack research on target organizations and employees, often gathering information from public sources like social networking and professional profiling platforms. The initial social engineering phase involves impersonating corporate IT help desks, urgently instructing employees to update their passkey, multi-factor authentication (MFA), or single sign-on (SSO) configurations to prevent access loss. Victims are subsequently directed to phishing sites designed to closely resemble legitimate Microsoft login portals, with links sometimes delivered via SMS messages.

The attackers focus on tricking victims into signing into adversary-in-the-middle (AiTM) phishing sites or engaging in device-code authentication flows, rather than attempting to enroll a passkey. AiTM attacks allow the threat actors to capture sensitive credentials and session tokens. The threat actors establish phishing domains that combine company names with terms related to passkeys, SSO, key synchronization, and identity verification, such as passkeyhelpdesk.com or integratedsso.com, often using the victim company name as a subdomain to enhance credibility.

In the post-compromise phase, Microsoft research details how attackers exploit the Microsoft cloud environment. In one observed attack, a session established after MFA allowed the attacker to access various resources, including My Apps, My Profile, and various management interfaces. Subsequently, the attacker accessed SharePoint Online, Outlook Web, Microsoft 365 collaboration, and internal business applications, listing sensitive files and internal application assignments over approximately one hour. Another technique involved device-code phishing, where victims entered codes provided by the attacker into legitimate Microsoft authentication pages, issuing an authentication token to the attacker-controlled OAuth application, thereby granting access to all connected SSO applications across platforms like Microsoft 365, Salesforce, and others.

Threat actors further leverage previously compromised credentials to perform reconnaissance using automated systems, including Node.js and the Microsoft Graph API. They utilize these tools to enumerate critical information within the enterprise environment, including organizational structures, licensed services, user and group memberships, directory roles, registered authentication methods, application assignments, and access to SharePoint sites, document libraries, OneDrive resources, and mailbox content in Exchange Online. This reconnaissance often involves rapid movement across different resources to check privileges and authentication settings.

Following reconnaissance, attackers focus on systematic data collection from Microsoft 365. Microsoft observed high-volume access and download activity targeting SharePoint Online and OneDrive for Business, with intrusions extending into Exchange Online via REST API access to email content. This activity generated significant FileAccessed and FileDownloaded events, indicating the systematic retrieval of cloud-hosted documents and organizational data, often executed automatically using connections employing the python-httpx user agent. To evade detection, the exfiltration process is designed to occur slowly, with threat actors accessing fewer than one thousand files or emails in a single hour.

Microsoft advises that administrators should look for specific anomalies, such as unusual sign-ins followed by new MFA registrations, suspicious use of Microsoft Graph for reconnaissance, and abnormal access to SharePoint, OneDrive, or Exchange. If an account is compromised, immediate remediation steps include revoking active sessions and tokens, resetting credentials, removing any authentication methods or mailbox rules added by the attackers, and forcing users to re-register their authentication methods. Furthermore, Microsoft recommends implementing phishing-resistant MFA, restricting sensitive cloud resources to managed devices, and disabling device-code authentication when it is not operationally necessary.