Threat actors are leveraging passkey phishing lures, device-code authentication flows, and automated Microsoft Graph API abuse to compromise corporate cloud tenants and exfiltrate sensitive data. Recent disclosures from Microsoft outline two distinct campaigns targeting enterprise organizations: one deploying large-scale business email compromise (BEC) financial fraud, and another using direct social engineering to bypass multi-factor authentication (MFA) and establish persistent access inside Microsoft 365 environments.
The campaigns highlight a growing shift in threat actor tactics. As organizations deploy stronger authentication mechanisms, attackers are adapting by using the terminology of modern security—specifically passkeys and SSO updates—as pretexts to manipulate end users into delegating access or completing authentication requests on the adversary’s behalf.
GenAI-Assisted Invoice Scams and Executive Impersonation
The first campaign focused heavily on financial fraud, blasting over one million scam emails between August 3 and August 5, 2026. The attackers targeted accounts payable and finance personnel across U.S. enterprise sectors, including IT services, consumer goods, real estate, and discrete manufacturing.
To execute the scheme, the operators abused legitimate third-party email delivery infrastructure to bypass basic domain reputation checks. The lure relied on fabricated invoices for annual ServiceNow subscriptions, directing finance departments to initiate Automated Clearing House (ACH) transfers to attacker-controlled accounts.
Generative artificial intelligence (AI) played a core role in drafting tailored email content, generating realistic invoice templates, and constructing multi-turn approval threads. The attackers harvested the names and business email addresses of executives—such as CEOs, CFOs, and presidents—plugging them directly into spoofed signature blocks and fake internal email chains to minimize target skepticism.
Passkey Social Engineering and Device-Code Exploitation
The second campaign, active since May 2026, relies on voice phishing (vishing) and SMS lures sent directly to employees’ personal phone numbers. Posing as internal IT help desk personnel, the attackers instruct victims to immediately update their passkey, MFA, or single sign-on (SSO) configuration to prevent impending account suspension.
Targets are directed to adversary-hosted phishing pages masquerading as official Microsoft login portals. The domains frequently follow a victim-tailored naming convention: <company name>.<malicious domain>[.]com.
Depending on the targeted workflow, the threat actors execute one of several initial access techniques:
- Adversary-in-the-Middle (AitM) Phishing: Intercepting credentials and session tokens in real time via reverse-proxy infrastructure.
- Device-Code Phishing: Prompting users to enter a device authorization code on a legitimate identity provider page. Because device-code authorization allows authentication from secondary devices, the victim unknowingly grants the attacker a valid token without handing over raw credentials or session cookies directly.
- Internal Teams Propagation: Once an initial account is compromised, the attackers use Microsoft Teams to send passkey-themed update requests to other employees within the target organization, abusing established internal trust.
Post-Compromise Persistence and Microsoft Graph Exfiltration
Once initial access is achieved, the threat actor’s immediate goal is establishing persistence before the primary session expires or the user changes their password. In many cases, the attacker registers a new authentication method under their own control—such as a new phone number, an authenticator app, or a software-based OTP token—on the compromised identity. This allows the adversary to log back into the tenant at will without requiring further victim interaction.
With persistent access secured, the actors pivot to automated reconnaissance and data harvesting using the Microsoft Graph API. Because individual API requests mimic legitimate administrative or user activity, the activity often evades traditional perimeter and rule-based detections.
Post-compromise activity observed in victim environments includes:
- Reconnaissance: Querying Graph APIs to enumerate tenant users, security groups, assigned administrative roles, internal permissions, and accessible resources.
- Mailbox Collection: Enumerating mailbox folders, message threads, and attachment metadata via REST APIs to gather sensitive operational intelligence.
- Mass Data Exfiltration: Executing high-volume, automated download requests against SharePoint Online, OneDrive for Business, and Exchange Online. Exfiltration streams often persist over several hours or days.
- Infrastructure Rotation: Splitting authentication, reconnaissance, and exfiltration traffic across distinct proxy IP addresses to prevent automated IP-based blocking.
Threat Actor Landscape and Attribution
Microsoft tracks the initial access activity across these campaigns under the designations Storm-3121 and Storm-3032.
Storm-3121 is known for performing initial access broker operations that hand off victim access to ransomware and extortion groups like ShinyHunters and Falcon (also tracked as CL-CRI-1182).
Storm-3032 corresponds to UNC6671, a group that splintered from BlackFile (CL-CRI-1116) and now operates under the Helix extortion brand. Broad community tracking aligns this activity with overlapping cybercrime umbrella groups, including Cordial Spider, O-UNC-045, and PREY-0058. These threat clusters frequently share commoditized phishing panels, infrastructure, and voice-phishing operators while operating distinct extortion storefronts.
Detection and Mitigation Strategies
Defending against passkey-themed phishing and Graph API abuse requires shifting detection strategies from single-indicator alerts to holistic behavioral monitoring.
- Restrict MFA Registration Policies: Implement Entra ID Conditional Access policies that restrict the registration of new security information (phone numbers, authenticator apps) to compliant or hybrid-joined devices, or require a Temporary Access Pass (TAP) issued by verified IT staff.
- Disable Unused Device-Code Flows: If device-code authentication is not strictly required for specific headless devices or CLI environments in your tenant, block the device-code flow entirely via Conditional Access.
- Holistic Graph API Monitoring: Traditional SIEM rules targeting individual API calls fail to flag this activity. Detection logic must correlate anomalous user behavior—such as a user authenticating from an unmanaged device followed immediately by high-volume REST API calls to SharePoint or Graph endpoints—and flag broad data enumeration spikes.
- FIDO2 and Passkey Hardware Enforcement: While attackers use passkeys as a social engineering lure, real FIDO2 hardware keys (YubiKeys) remain resistant to AitM and device-code phishing when strictly enforced via Certificate-Based Authentication or FIDO2-only Conditional Access policies.
Related content
Microsoft 365 AitM Phishing Campaign Targets Payroll and Finance Emails
Security NewsHealth-ISAC Warns Healthcare Sector of Escalating ShinyHunters SSO Vishing Attacks
Security NewsBlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Prior to Malware Delivery
Security NewsAttackers Spoof OAuth Client IDs to Evade Microsoft Cloud Sign-in Logs
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call