www.microsoft.com 9 Sept 2026, 17:41 UTC

Microsoft Exposes Passkey Bait Campaign Targeting Microsoft 365 Data

Microsoft Exposes Passkey Bait Campaign Targeting Microsoft 365 Data
CyberSIXT Evidence Panel Source marked as original reporting

MICROSOFT Security Research outlines a multi-stage cloud intrusion campaign that begins with passkey-themed social engineering and culminates in identity compromise, persistence, reconnaissance, and targeted data exfiltration across Microsoft 365 workloads. Since May 2026, threat actors have leveraged seemingly legitimate helpdesk-style outreach to lure users into signing in via fake portals, enabling AiTM phishing or device-code flows that capture credentials and tokens.

In many cases, passkey enrollment is a pretext; the objective is to gain access to Microsoft Graph, SharePoint, OneDrive and related services, while avoiding easy endpoint detection on unmanaged devices. The attackers rapidly shifted infrastructure, using themed domains and impersonation to stay credible as they pivot from sign-ins to data collection.

The activity progresses from initial access to internal reconnaissance and data exfiltration. Investigations describe sessions where compromised identities enumerate tenant resources, access SharePoint and OneDrive content, and reach Exchange Online via REST APIs. A common persistence tactic is MFA method reconfiguration, with attackers enrolling new devices or software tokens to sustain access.

Graph reconnaissance and content discovery are carried out in staged waves, with evidence of automation and rotating IPs to blend with normal usage. High-volume data collection targets SharePoint Online and OneDrive, with some activity extending to Exchange Online; in several cases, python-httpx was used to drive large-scale downloads while remaining under notice thresholds.

Defence guidance emphasises treating Graph activity holistically, revoking sessions, removing attacker-authentication methods, and enforcing phishing-resistant MFA with conditional access. Recommendations include restricting unmanaged devices, auditing Graph activity, and alerting on anomalous sign-ins, MFA changes, and large-scale file or mailbox access.

The report attributes initial access to groups including Storm-3121 and Storm-3032, and stresses coordinated detection across identity, Graph, and SaaS data signals.

View full article

Article by CyberSIXT