Skip to content
Auto-CTI
Back to today
NEW HIGH C3

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

C The Hacker News ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

The report shows that even phishing-resistant passkeys can be bypassed through social engineering and abused email delivery infrastructure to take over Microsoft cloud accounts.

Description

Microsoft describes two active campaigns in which attackers abuse third-party email infrastructure. In the first campaign, more than one million scam messages impersonating executives are sent between August 3 and 5, 2026. The second campaign uses passkey-themed social engineering to gain access to Microsoft cloud accounts and then exfiltrate data. The attacks rely on identity deception and legitimate delivery paths rather than an exploitable software vulnerability; no CVEs are named. Microsoft cloud environments are affected, where credentials or sessions are captured via phishing.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC