logo

Microsoft Self-Service Password Reset abused in Azure data theft attacks

ID: 056be8d7-7f9e-5bf8-b222-3a60afbcf172

STIX ID: report--056be8d7-7f9e-5bf8-b222-3a60afbcf172

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Bill Toulas

...
...

Microsoft reports that the actor Storm-2949 used social engineering to hijack privileged Microsoft Entra accounts, abused SSPR/MFA flows and enrolled authenticators, then used Microsoft Graph, custom Python scripts, and Azure RBAC abuse to enumerate resources, exfiltrate OneDrive/SharePoint data, steal Key Vault secrets and storage credentials, and deploy remote access tooling to persist and remove evidence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.