Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts

Microsoft disclosed campaigns where attackers exploited third-party email systems for large-scale financial scam phishing and used passkey-themed social engineering techniques to compromise cloud accounts.

Why it matters

The campaigns combine widespread phishing with sophisticated social engineering targeting passkeys, significantly increasing the risk of unauthorized access within Microsoft cloud environments.

SOC impact

Investigate phishing activity involving CEO impersonation emails and monitor for suspicious passkey enrollment or use in cloud accounts. Verify impacted assets and review email gateway telemetry to identify potential abuse of third-party systems.

Recommended actions

  1. Review email logs for indicators of CEO impersonation phishing campaigns
  2. Monitor authentication and enrollment logs for unusual passkey activity
  3. Identify and assess cloud accounts targeted by passkey phishing
  4. Analyze third-party email system interactions for signs of exploitation
  5. Confirm the presence and scope of affected cloud resources

Executive Summary

In September 2026, Microsoft revealed two coordinated campaigns leveraging third-party email systems to conduct financial scam phishing at scale. Over one million scam emails impersonated CEOs to initiate these attacks. Furthermore, attackers employed passkey-themed social engineering techniques to hijack Microsoft cloud accounts, escalating the operational risk for enterprises using these services. This blend of mass phishing and advanced access compromise methods underscores the evolving threat landscape facing cloud environments.

SOC Impact

Investigate phishing activity involving CEO impersonation emails and monitor for suspicious passkey enrollment or use in cloud accounts. Verify impacted assets and review email gateway telemetry to identify potential abuse of third-party systems.

Phishing and Cloud Account Validation

  • Review email logs for indicators of CEO impersonation phishing campaigns
  • Monitor authentication and enrollment logs for unusual passkey activity
  • Identify and assess cloud accounts targeted by passkey phishing
  • Analyze third-party email system interactions for signs of exploitation
  • Confirm the presence and scope of affected cloud resources

Why It Matters

The campaigns combine widespread phishing with sophisticated social engineering targeting passkeys, significantly increasing the risk of unauthorized access within Microsoft cloud environments.

Source