Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Image for article Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
News Source : Internet

News Summary

  • Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure.
  • The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026.
  • The second campaign revolves around cloud-based intrusions targeting multiple accounts in which suspicious sign-ins are followed by the threat actors adding their own authentication methods.
  • The activity primarily singled out enterprise users in the u.s., spanning IT services, consumer goods, real estate, and discrete manufacturing sectors.

Must read Articles