Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft has revealed two distinct cyber campaigns: one involving AI-generated financial fraud emails impersonating CEOs for ACH transfers, and another using passkey-themed social engineering to compromise Microsoft cloud accounts and exfiltrate data.
Intelligence analysis by Gemini 2.5 Flash

Threat actors are employing sophisticated social engineering tactics, including generative AI for convincing financial fraud emails and passkey-themed phishing to bypass multi-factor authentication. These campaigns target enterprise users, aiming to trick finance departments into making fraudulent payments or to gain unauthorized access to cloud environments for data exfiltration.
Imagine a sneaky trickster who pretends to be your boss or the school's computer helper. They send you fake messages, either asking you to pay for something that isn't real, or telling you to click a link to update your secret password key. If you fall for it, they can either steal your money or sneak into your online accounts, like your school's computer system, and look at your files. It's like someone pretending to be a trusted friend to get your house key.
Analysis
Microsoft has brought to light two significant and distinct cyber campaigns that underscore the escalating sophistication of threat actors targeting enterprise environments. The first campaign, a large-scale financial fraud operation, leveraged generative AI to craft highly convincing scam emails. These emails, sent to over a million recipients, impersonated CEOs and targeted accounts payable departments, attempting to induce them into initiating fraudulent Automated Clearing House (ACH) transfers for a fictitious ServiceNow annual subscription. The attackers meticulously registered impersonation domains, embedded fabricated invoices, and even included forged email threads to create a compelling narrative, significantly reducing recipient skepticism compared to traditional invoice scams.
ServiceNow Annual Subscription
This financial fraud campaign demonstrated a high degree of planning and execution. Threat actors registered domains like service-nowinc[.]com to appear legitimate, then sent executive-themed payment requests through trusted infrastructure. The use of generative AI for email template creation and tailored drafting allowed for a personalized approach, making the scam more difficult to detect. The campaign specifically targeted enterprise users in the U.S. across various sectors, including IT services, consumer goods, real estate, and manufacturing, indicating a broad and strategic targeting methodology.
Microsoft Graph Activity
The second campaign detailed by Redmond focuses on cloud-based intrusions, primarily targeting Microsoft accounts through passkey-themed social engineering. Attackers would contact users via personal phone numbers, posing as IT help desk personnel, and urge them to update their passkey, MFA, or SSO configurations to avoid access disruptions. Unsuspecting employees were then redirected to counterfeit Microsoft sign-in pages via SMS, where adversary-in-the-middle (AitM) or device-code authentication flows were used to capture credentials or grant unauthorized access. This activity often led to high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and mailbox collection via REST APIs, indicating a clear intent for data exfiltration.
UNC6671
Microsoft's analysis reveals that the modus operandi of the passkey phishing campaign overlaps with a known cybercrime collective tracked under various monikers, including Cordial Spider, O-UNC-045, PREY-0058, and UNC6671. This group is known for operating multiple public extortion brands and sharing underlying phishing infrastructure. The threat actor invests heavily in pre-attack research, gathering information about employees and organizational structures from public sources to facilitate targeted voice phishing campaigns. Microsoft has attributed initial access activity in this campaign to specific threat actors like Storm-3121 and Storm-3032, with Storm-3032 being a designation for UNC6671, highlighting the interconnected nature of these sophisticated cybercriminal operations.
Key points
- Attackers are using generative AI to create highly convincing financial fraud emails impersonating CEOs for ACH transfer scams.
- A second campaign employs passkey-themed social engineering and adversary-in-the-middle (AitM) techniques to hijack Microsoft cloud accounts.
- Compromised cloud accounts lead to high-volume Microsoft Graph activity, SharePoint/OneDrive downloads, and mailbox collection.
- The passkey phishing campaign's tactics overlap with a known cybercrime collective tracked as Cordial Spider, O-UNC-045, PREY-0058, and UNC6671.
- Threat actors conduct extensive pre-attack research, gathering employee and organizational data from public sources to tailor their attacks.
Microsoft's detailed disclosure of these campaigns provides critical intelligence, enabling organizations to bolster their defenses against similar sophisticated social engineering and phishing attacks. Increased awareness and implementation of robust security training for employees can significantly reduce the success rate of such deceptive tactics.
The use of generative AI makes financial fraud emails exceptionally convincing, while passkey-themed phishing directly targets advanced authentication methods, posing a persistent and evolving threat to cloud security. Organizations face an uphill battle in training employees to identify increasingly sophisticated lures and protecting against credential theft.


