Passkey-themed phishing attacks lead to Microsoft 365 data theft
Executive Summary
Threat actors linked to ShinyHunters, Helix, and other extortion gangs are exploiting passkey and single sign‑on themes in social engineering campaigns to compromise corporate Microsoft accounts. By tricking users into revealing credentials, attackers gain access to Microsoft 365 services and exfiltrate sensitive data. Microsoft has warned organizations to verify authentication requests and strengthen security controls.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-11T17:26:50+00:00 - Category: threat-intel
Original Description: Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]
"Accept challenges, so that you may feel the exhilaration of victory."
— George Patton