Microsoft has unveiled details of two significant hacking operations where attackers exploited third-party email systems to distribute financial fraud schemes and used passkey-themed deception to infiltrate cloud systems. These malicious campaigns have raised alarms in the cybersecurity community due to their sophisticated methods and extensive reach.
Financial Fraud Campaigns Target Enterprises
The first operation involved a barrage of phishing emails, impersonating CEOs of target companies, sent between August 3 and 5, 2026. The emails aimed to deceive accounts payable departments into executing Automated Clearing House (ACH) transfers for a fake ServiceNow subscription. With over a million emails sent, the operation heavily targeted U.S.-based enterprises in sectors like IT services and consumer goods.
The attackers crafted these emails using generative AI, creating tailored templates for each recipient. This campaign involved registering domains to mimic legitimate businesses, sending payment requests, and incorporating fake invoices to appear credible. The emails even included forged threads to lend authenticity, tricking recipients into transferring funds to accounts controlled by the attackers.
Passkey-Themed Social Engineering Attacks
In a parallel campaign, attackers focused on compromising cloud accounts by leveraging identity-themed social engineering tactics. This involved contacting employees via phone or messaging, posing as IT support, and urging immediate passkey updates. The unsuspecting victims were redirected to fake Microsoft sign-in pages, facilitating adversary-in-the-middle (AitM) attacks.
The attackers targeted multiple accounts and added their authentication methods, leading to unauthorized access to Microsoft Graph, SharePoint, and OneDrive. This activity, ongoing since May 2026, illustrates a sophisticated method of bypassing security protocols to gain control over cloud accounts, enabling extensive data extraction.
Threat Actor Tactics and Implications
Microsoft identified these campaigns as part of larger operations by cybercrime collectives such as Cordial Spider and UNC6671. These groups employ credential harvesting techniques and utilize generic domains to conduct voice phishing campaigns. The attackers have been observed using compromised credentials to register new authentication methods, bypassing multi-factor authentication (MFA).
Once access is gained, the threat actors conduct detailed reconnaissance using the Graph API, assessing roles, and collecting intelligence from mailbox messages and SharePoint. The attacks are meticulously planned, with infrastructure rotation to evade detection, underscoring the need for holistic assessment of Graph activity for effective threat detection.
These campaigns highlight a critical challenge in detecting Microsoft Graph abuse, emphasizing the importance of behavioral analysis over isolated API calls. As cyber threats become more sophisticated, organizations must prioritize comprehensive security measures to safeguard their cloud environments.
