Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Executive Summary

Microsoft disclosed two campaigns in which threat actors abused third‑party email delivery services to send over a million financial‑fraud scam emails (Aug 3‑5 2026) masquerading as CEOs. The attackers used passkey‑themed social engineering to breach Microsoft cloud environments and exfiltrate data. The incidents highlight the use of legitimate email infrastructure for credential‑stealing and data theft.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-13T10:11:48+00:00 - Category: threat-intel

Original Description: Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers

"Learn wisdom from the ways of a seedling. A seedling which is never hardened off through stressful situations will never become a strong productive plant."

— Stephen Sigmund
Source: The Hacker News