securityonline.info 10 Sept 2026, 02:02 UTC

Microsoft Warns Passkey Scams Are Breaching Cloud Tenants

Microsoft Warns Passkey Scams Are Breaching Cloud Tenants
CyberSIXT Evidence Panel
Threat Actor
Storm-3121

MICROSOFT threat intelligence has flagged active cloud intrusions that abuse passkey social engineering to breach enterprise tenants, with observations dating to 9 September 2026. The campaigns, linked to Storm-3121 and Storm-3032 (Helix) and related extortion groups, combine voice phishing with automated data theft from cloud services.

Targeted employees across corporate tenants—including executives and IT staff—have seen sessions tokens and authentication approvals siphoned, enabling access to SharePoint, OneDrive and Exchange data.

The attackers contact staff posing as internal IT helpdesk, create urgent prompts to update security credentials, and direct victims to fake authentication portals or adversary-in-the-middle sites. In device-code and passkey-related flows, victims enter codes on official Microsoft pages, allowing attacker-controlled clients to obtain authorisation. The intruders then register actor-controlled MFA factors to maintain persistence, so access persists even if the victim changes their password.

Microsoft Graph is used to enumerate tenant resources—users, groups, permissions, document libraries, and email contents—while traffic is rotated across IPs to evade detection. Reported exfiltration is deliberate rather than bulk, with attackers typically harvesting under 1,000 files or emails per hour over several days, including mailboxes via One Outlook Web access, supporting extortion demands.

Defensive guidance focuses on phishing-resistant MFA (preferably hardware-based), restricting device-code flow permissions, auditing for new authenticator registrations, monitoring Graph audit logs for unusual activity, and training staff to verify helpdesk communications through official channels. The report emphasises stopping these chains before data exfiltration begins.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline