Cybercriminals Exploit Passkey Lures to Breach Corporate Microsoft Accounts

Microsoft has observed a campaign since May 2026 where extortion groups impersonate IT help desks to trick employees into visiting phishing sites that mimic Microsoft login pages. The attackers use passkey and single sign-on themes to capture credentials or abuse device-code authentication flows, often sending links via SMS to personal phones. They conduct extensive pre-attack research on targets and register domains that combine company names with passkey-related terms to appear legitimate.
The campaign relies on thorough pre-attack reconnaissance, using public professional profiles to single out specific employees. Attackers send SMS links to personal devices, steering victims to domains that merge corporate names with passkey or SSO terminology. Microsoft attributes this to Storm-3121 and Storm-3032, linked to ShinyHunters, Falcon, and Helix extortion groups.
After breaching accounts, attackers sign in from unmanaged devices to OfficeHome, then probe My Apps, My Profile, and approval management interfaces to map available resources. This activity overlaps with Google's UNC6671 cluster, which ties the same infrastructure to BlackFile, Pink, and Redact extortion operations.
This campaign could significantly disrupt corporate data security, as employees are trained to trust IT help desks and passkey updates. If successful, extortion groups may exfiltrate sensitive business data, causing financial and reputational damage. The use of personal phones for phishing links also blurs work and personal security boundaries, potentially exposing employees' private devices to compromise.