Technology

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

The Hacker News September 13, 2026 5 views
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Advertisement

Microsoft has revealed details of two significant cyber campaigns where attackers exploited third-party email delivery systems to disseminate financial fraud scams and employed passkey-themed social engineering tactics to infiltrate cloud environments.

In the first campaign, threat actors sent more than a million fraudulent emails over a brief period from August 3 to August 5, 2026. These emails were crafted to appear as if they were sent by chief executive officers, a common tactic aimed at deceiving recipients into trusting the message's authenticity.

The tech giant has highlighted the sophistication of these campaigns, noting the use of passkey-themed social engineering methods. Such techniques are designed to manipulate users into revealing sensitive information, which can then be used to breach cloud systems and exfiltrate data.

Microsoft's disclosure underscores the ongoing challenges in cybersecurity, particularly the evolving strategies that threat actors employ to compromise systems. The use of third-party email infrastructure in these campaigns illustrates the lengths to which attackers will go to bypass traditional security measures.

Organizations are advised to remain vigilant and enhance their security protocols to defend against such threats. This includes educating employees about the dangers of phishing and implementing robust authentication mechanisms to protect sensitive information.

<small>Source: The Hacker News — read the original story there.</small>

How did this make you feel?

Never miss a story

Get the best of SpeakOX in your inbox. No spam, unsubscribe anytime.

Advertisement

Category
Technology

Advertisement