Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Passkey Phishing Exploits Target Microsoft Cloud Accounts

Passkey Phishing Exploits Target Microsoft Cloud Accounts

Posted on September 13, 2026 By CWS

Microsoft has unveiled details of two significant hacking operations where attackers exploited third-party email systems to distribute financial fraud schemes and used passkey-themed deception to infiltrate cloud systems. These malicious campaigns have raised alarms in the cybersecurity community due to their sophisticated methods and extensive reach.

Financial Fraud Campaigns Target Enterprises

The first operation involved a barrage of phishing emails, impersonating CEOs of target companies, sent between August 3 and 5, 2026. The emails aimed to deceive accounts payable departments into executing Automated Clearing House (ACH) transfers for a fake ServiceNow subscription. With over a million emails sent, the operation heavily targeted U.S.-based enterprises in sectors like IT services and consumer goods.

The attackers crafted these emails using generative AI, creating tailored templates for each recipient. This campaign involved registering domains to mimic legitimate businesses, sending payment requests, and incorporating fake invoices to appear credible. The emails even included forged threads to lend authenticity, tricking recipients into transferring funds to accounts controlled by the attackers.

Passkey-Themed Social Engineering Attacks

In a parallel campaign, attackers focused on compromising cloud accounts by leveraging identity-themed social engineering tactics. This involved contacting employees via phone or messaging, posing as IT support, and urging immediate passkey updates. The unsuspecting victims were redirected to fake Microsoft sign-in pages, facilitating adversary-in-the-middle (AitM) attacks.

The attackers targeted multiple accounts and added their authentication methods, leading to unauthorized access to Microsoft Graph, SharePoint, and OneDrive. This activity, ongoing since May 2026, illustrates a sophisticated method of bypassing security protocols to gain control over cloud accounts, enabling extensive data extraction.

Threat Actor Tactics and Implications

Microsoft identified these campaigns as part of larger operations by cybercrime collectives such as Cordial Spider and UNC6671. These groups employ credential harvesting techniques and utilize generic domains to conduct voice phishing campaigns. The attackers have been observed using compromised credentials to register new authentication methods, bypassing multi-factor authentication (MFA).

Once access is gained, the threat actors conduct detailed reconnaissance using the Graph API, assessing roles, and collecting intelligence from mailbox messages and SharePoint. The attacks are meticulously planned, with infrastructure rotation to evade detection, underscoring the need for holistic assessment of Graph activity for effective threat detection.

These campaigns highlight a critical challenge in detecting Microsoft Graph abuse, emphasizing the importance of behavioral analysis over isolated API calls. As cyber threats become more sophisticated, organizations must prioritize comprehensive security measures to safeguard their cloud environments.

The Hacker News Tags:cloud accounts, cloud security, cyber attack, Cybersecurity, data breach, email delivery, email scams, identity theft, IT security, MFA, Microsoft, passkey phishing, Phishing, social engineering, Threat Actors

Post navigation

Previous Post: Plesk Backup Manager Vulnerability Exposes Servers to Risk

Related Posts

Lumen Technologies Reinvents Exposure Management Strategy Lumen Technologies Reinvents Exposure Management Strategy The Hacker News
UNC6671 Cyber Threat Intensifies with Vishing Attacks UNC6671 Cyber Threat Intensifies with Vishing Attacks The Hacker News
KadNap Malware Uses Asus Routers for Stealth Botnet KadNap Malware Uses Asus Routers for Stealth Botnet The Hacker News
CISA Identifies Critical Flaws in ConnectWise and Windows CISA Identifies Critical Flaws in ConnectWise and Windows The Hacker News
CISA Urges Action on Severe Ray Vulnerability CISA Urges Action on Severe Ray Vulnerability The Hacker News
PhantomCore Exploits Russian Video Conferencing Software PhantomCore Exploits Russian Video Conferencing Software The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Passkey Phishing Exploits Target Microsoft Cloud Accounts
  • Plesk Backup Manager Vulnerability Exposes Servers to Risk
  • Revolut Data Breach: Sensitive Customer Info Exposed
  • CISA Highlights Critical Security Flaws in Artifactory and RouterOS
  • VLC Media Player Security Flaws Pose Serious Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Passkey Phishing Exploits Target Microsoft Cloud Accounts
  • Plesk Backup Manager Vulnerability Exposes Servers to Risk
  • Revolut Data Breach: Sensitive Customer Info Exposed
  • CISA Highlights Critical Security Flaws in Artifactory and RouterOS
  • VLC Media Player Security Flaws Pose Serious Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark