Cybersecurity

Attacks Impersonating Passkey Updates to Steal Microsoft 365 Identities and Cloud Data

Microsoft Security Research observed a series of intrusions that begin with calls and messages impersonating IT support, then exploit AiTM or device code flows to add an attacker-controlled MFA method, explore Microsoft Graph, and extract SharePoint, OneDrive, and email data. Microsoft says the activity has been ongoing since May 2026 and aims to turn temporary identity compromise into persistent cloud access.

2026-09-09
4 min read
6 views
فريق تحرير certi.news
Attacks Impersonating Passkey Updates to Steal Microsoft 365 Identities and Cloud Data

Microsoft Security Research observed an active pattern of cloud intrusions that begins by convincing an employee that they need to update their passkey, multifactor authentication (MFA), or single sign-on (SSO), before turning into identity compromise and access to Microsoft 365 data. According to the company, this activity has been observed since May 2026 across multiple accounts, followed by unusual sign-ins, the addition of new authentication methods, extensive reconnaissance using Microsoft Graph, and then access to SharePoint and OneDrive files and email content.

Passkey registration is often not the actual objective. Attackers use the topic as a pretext to direct the victim to phishing pages or a device code flow. In adversary-in-the-middle (AiTM) attacks, credentials and session tokens can be intercepted, while in a device code attack, the user unknowingly approves granting an attacker-controlled client an access token to the permitted resources.

From a Phone Call to Identity Control

The campaign often begins with a call or message to the employee’s personal phone number from someone impersonating the help desk, creating a sense of urgency. The phishing link may be sent by SMS to the personal phone, reducing the evidence visible in device-monitoring tools if the phone is not enrolled in Microsoft Defender for Endpoint. Microsoft also observed similar messages through Microsoft Teams from compromised employee accounts, which increases the request’s credibility.

Attackers leverage publicly available information about employees and the organization’s structure, and create rapidly changing domains that place the organization’s name in a subdomain, such as the companyname.maliciousdomain.com pattern. Microsoft emphasizes that the registration of some of these domains with a particular registrar is not evidence of the registrar’s involvement.

Adding MFA and Then Reconnoitering the Cloud Environment

After gaining access, the attacker seeks to establish persistence by registering a phone number, authenticator app, or software OTP under their control. Investigations found cases in which sessions lasting about an hour were used to browse administrative applications and internal files, as well as cases in which compromised credentials were reused after the authenticator app had been registered days earlier.

Microsoft Graph is subsequently used to inventory users, groups, roles, applications, services, sites, and mailboxes. Microsoft considers a single request to paths such as /users or /groups potentially normal, but a sequence of requests from the same identity, application, or access token across multiple categories, followed by a transition to files and email, is a stronger indicator of reconnaissance followed by data collection.

Gradual Collection of Files and Email

After reconnaissance, the company observed high-volume activity involving access to and downloads of SharePoint and OneDrive files, in addition to email collection through REST APIs in some cases. Indicators of automation appeared, including use of a user agent named python-httpx, but Microsoft warns that this should not be considered sufficient evidence on its own. Data was also collected at a measured pace; some operations remained below 1,000 files or messages per hour and continued for hours to days, which may make them less conspicuous than a rapid extraction operation.

What Should Defense Teams Monitor?

  • Correlate unusual sign-ins with the addition of authentication methods, token issuance, Microsoft Graph activity, and SaaS or email downloads.
  • Review new authentication methods and devices and remove unauthorized ones, then revoke sessions and tokens and reset credentials for confirmed compromised accounts.
  • Apply phishing-resistant MFA, require managed and compliant devices, and restrict security-information registration and device code flows when there is no clear business need.
  • Review application consent and services with sensitive Graph permissions, enable Graph activity logs, audit mailboxes, and alert on unusual reconnaissance and downloads.

Editorial reading: The most important change here is not the appearance of a new phishing page, but the attack’s transition from deceiving the user to exploiting identity as an integrated pathway: establishing MFA, then conducting reconnaissance, and finally collecting data. Therefore, matching a single domain or IP address is not enough; defensive effectiveness depends on correlating identity signals, cloud interfaces, and access behavior. Microsoft attributes the initial activity to a number of groups, including Storm-3121 and Storm-3032, while noting that the attribution is not limited to them.

News source
Microsoft Security Blog
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news