Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
News Source : Internet
News Summary
- Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure.
- The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026.
- The second campaign revolves around cloud-based intrusions targeting multiple accounts in which suspicious sign-ins are followed by the threat actors adding their own authentication methods.
- The activity primarily singled out enterprise users in the u.s., spanning IT services, consumer goods, real estate, and discrete manufacturing sectors.
Never miss a story from us, subscribe to our newsletter