THREATOPS
THREAT OPSThreat News › Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

lowthehackernewsPublished 2026-09-13

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments.

The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers

MITRE ATT&CK techniques

Original source: https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html