logo

Passkey-themed phishing attacks lead to Microsoft 365 data theft

ID: 825ecf05-301e-5c1e-8515-bfeb693bf359

STIX ID: report--825ecf05-301e-5c1e-8515-bfeb693bf359

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-09-11

Date Updated: 2026-09-11

Author: Lawrence Abrams

...
...

Microsoft reports that extortion-linked threat actors (including clusters tracked as Storm-3121/Storm-3032 and overlapping with UNC6671) have used passkey- and SSO-themed phone/SMS social engineering, adversary-in-the-middle (AiTM) and device-code phishing since May 2026 to compromise corporate Microsoft 365 accounts, perform Microsoft Graph reconnaissance, add attacker-controlled authentication methods for persistence, and systematically exfiltrate files from SharePoint, OneDrive and Exchange while registering convincing phishing domains and using automated access patterns to blend in with legitimate traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.