Passkey-themed phishing attacks lead to Microsoft 365 data theft
ID: 825ecf05-301e-5c1e-8515-bfeb693bf359
STIX ID: report--825ecf05-301e-5c1e-8515-bfeb693bf359
Feed Name: Bleeping Computer
Microsoft reports that extortion-linked threat actors (including clusters tracked as Storm-3121/Storm-3032 and overlapping with UNC6671) have used passkey- and SSO-themed phone/SMS social engineering, adversary-in-the-middle (AiTM) and device-code phishing since May 2026 to compromise corporate Microsoft 365 accounts, perform Microsoft Graph reconnaissance, add attacker-controlled authentication methods for persistence, and systematically exfiltrate files from SharePoint, OneDrive and Exchange while registering convincing phishing domains and using automated access patterns to blend in with legitimate traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
