Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
ID: 3b861e93-896b-5d4d-9b71-15775703c751
STIX ID: report--3b861e93-896b-5d4d-9b71-15775703c751
Feed Name: cybersecurityNews.com
Microsoft researchers observed a passkey-themed phishing campaign that lures employees via calls and texts to fake sign-in pages or device-code flows, enabling attackers to bypass MFA and steal usable cloud sessions; attackers then use Microsoft Graph to enumerate accounts and exfiltrate files and emails from SharePoint, OneDrive, and Exchange while maintaining persistence by registering rogue auth methods. The report includes observed indicators (defanged domains), detection and remediation guidance (revoke sessions, remove unauthorized auth methods, require phishing‑resistant MFA, restrict device‑code flows), and recommends correlating identity, Graph, and cloud audit logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
