Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
C The Hacker News ·
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
The report shows that even phishing-resistant passkeys can be bypassed through social engineering and abused email delivery infrastructure to take over Microsoft cloud accounts.
Description
Microsoft describes two active campaigns in which attackers abuse third-party email infrastructure. In the first campaign, more than one million scam messages impersonating executives are sent between August 3 and 5, 2026. The second campaign uses passkey-themed social engineering to gain access to Microsoft cloud accounts and then exfiltrate data. The attacks rely on identity deception and legitimate delivery paths rather than an exploitable software vulnerability; no CVEs are named. Microsoft cloud environments are affected, where credentials or sessions are captured via phishing.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 0.00
- industry weight
- 1.21
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
Path: operational