MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-11 · via BleepingComputer

Cybercriminals Exploit Passkey Lures to Breach Corporate Microsoft Accounts

Image via BleepingComputer
Image via BleepingComputer

Microsoft has observed a campaign since May 2026 where extortion groups impersonate IT help desks to trick employees into visiting phishing sites that mimic Microsoft login pages. The attackers use passkey and single sign-on themes to capture credentials or abuse device-code authentication flows, often sending links via SMS to personal phones. They conduct extensive pre-attack research on targets and register domains that combine company names with passkey-related terms to appear legitimate.

Expanded Detail

The campaign relies on thorough pre-attack reconnaissance, using public professional profiles to single out specific employees. Attackers send SMS links to personal devices, steering victims to domains that merge corporate names with passkey or SSO terminology. Microsoft attributes this to Storm-3121 and Storm-3032, linked to ShinyHunters, Falcon, and Helix extortion groups.

After breaching accounts, attackers sign in from unmanaged devices to OfficeHome, then probe My Apps, My Profile, and approval management interfaces to map available resources. This activity overlaps with Google's UNC6671 cluster, which ties the same infrastructure to BlackFile, Pink, and Redact extortion operations.

Context

This campaign could significantly disrupt corporate data security, as employees are trained to trust IT help desks and passkey updates. If successful, extortion groups may exfiltrate sensitive business data, causing financial and reputational damage. The use of personal phones for phishing links also blurs work and personal security boundaries, potentially exposing employees' private devices to compromise.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
ShinyHunters Claims Theft of 200,000 Records from Florida DMV Database · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Passkey-themed phishing attacks lead to Microsoft 365 data theft.” Browse more stories.