Microsoft says threat actors linked to ShinyHunters, Helix and other extortion gangs are using passkey- and single sign-on-themed social engineering to compromise corporate accounts and steal data from Microsoft 365 services.
Observed since May 2026, the campaign starts with research into targeted organizations and employees. Attackers then call or message victims while posing as corporate IT help desks, claiming that an urgent passkey, multi-factor authentication (MFA) or single sign-on (SSO) update is required. Victims are sent to imitation Microsoft login pages, sometimes through SMS messages to personal phones.
Microsoft says the attackers are not enrolling passkeys. Instead, the lures direct victims to adversary-in-the-middle (AiTM) phishing sites or device-code authentication flows that capture credentials, session tokens or access approvals.
Microsoft attributes the activity to several actors, including Storm-3121 and Storm-3032, and says it overlaps with Google Threat Intelligence's UNC6671 cluster. In one investigation, an attacker used a compromised session for approximately one hour to inspect assigned applications, organizational information, cloud services and sensitive files. Attackers also use Microsoft Graph to map cloud environments and may add phone numbers, authenticator apps or software-based one-time-password tokens as MFA methods they control.
Comments
0No comments yet. Be the first to comment.