Microsoft: Microsoft Cloud accounts stolen in highly complex impersonation and passkey phishing campaign

Microsoft: Microsoft Cloud accounts stolen in highly complex impersonation and passkey phishing campaign

Microsoft Warns of Sophisticated Phishing Campaign Targeting Passkey and MFA Users

Microsoft has uncovered a highly targeted cyberattack campaign tricking users into updating passkeys or multi-factor authentication (MFA) credentials via fake IT support calls. The operation, active since at least May 2024, leverages adversary-in-the-middle (AitM) techniques to compromise cloud accounts and exfiltrate sensitive data.

Attackers begin by conducting extensive reconnaissance, gathering details such as victims’ workplaces, job roles, and personal phone numbers from public sources like social media and professional networks. In some cases, they exploit already compromised accounts to expand their reach, sending passkey-themed phishing messages via Microsoft Teams.

The attack unfolds with a phone call victims are contacted by someone posing as their organization’s IT help desk, urging an immediate passkey or MFA update to avoid service disruptions. A follow-up SMS directs them to a fraudulent Microsoft login page, which appears legitimate but instead captures credentials or grants attackers access.

Once inside, threat actors target SharePoint, OneDrive, and Microsoft Exchange Online to steal files and email data. While Microsoft has not attributed the campaign to a specific group, it notes similarities to activities by known collectives like Cordial Spider and Storm-3121. The company advises organizations to adopt phishing-resistant MFA to mitigate such threats.

Source: https://www.techradar.com/pro/security/microsoft-cloud-accounts-stolen-in-highly-complex-impersonation-and-passkey-phishing-campaign

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-security

"id": "mic1789410611",
"linkid": "microsoft-security",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'location': 'Global',
                        'name': 'Microsoft Customers (Organizations and '
                                'Individuals)',
                        'type': 'Organizations, Individuals'}],
 'attack_vector': 'Social Engineering (Phone Calls, SMS, Microsoft Teams), '
                  'Adversary-in-the-Middle (AitM)',
 'data_breach': {'data_exfiltration': 'Yes',
                 'sensitivity_of_data': 'High (sensitive business data)',
                 'type_of_data_compromised': ['Files', 'Email data']},
 'date_detected': '2024-05-01',
 'description': 'Microsoft has uncovered a highly targeted cyberattack '
                'campaign tricking users into updating passkey or multi-factor '
                'authentication (MFA) credentials via fake IT support calls. '
                'The operation leverages adversary-in-the-middle (AitM) '
                'techniques to compromise cloud accounts and exfiltrate '
                'sensitive data.',
 'impact': {'data_compromised': 'Sensitive files, email data',
            'identity_theft_risk': 'High (account credentials compromised)',
            'operational_impact': 'Cloud account compromise, unauthorized data '
                                  'access',
            'systems_affected': ['SharePoint',
                                 'OneDrive',
                                 'Microsoft Exchange Online']},
 'initial_access_broker': {'entry_point': 'Compromised accounts, social media '
                                          'reconnaissance',
                           'high_value_targets': 'Cloud accounts (SharePoint, '
                                                 'OneDrive, Exchange Online)'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Organizations should adopt phishing-resistant MFA to '
                    'mitigate AitM attacks. Awareness of social engineering '
                    'tactics is critical.',
 'motivation': 'Data exfiltration, account compromise',
 'post_incident_analysis': {'corrective_actions': 'Adoption of '
                                                  'phishing-resistant MFA, '
                                                  'user training',
                            'root_causes': 'Lack of phishing-resistant MFA, '
                                           'human susceptibility to social '
                                           'engineering'},
 'recommendations': 'Implement phishing-resistant MFA, educate users on '
                    'recognizing fake IT support calls, monitor for unusual '
                    'account activity.',
 'references': [{'source': 'Microsoft Security Blog'}],
 'response': {'communication_strategy': 'Microsoft advisory to adopt '
                                        'phishing-resistant MFA'},
 'stakeholder_advisories': 'Microsoft advises organizations to adopt '
                           'phishing-resistant MFA.',
 'threat_actor': ['Cordial Spider', 'Storm-3121'],
 'title': 'Sophisticated Phishing Campaign Targeting Passkey and MFA Users',
 'type': 'Phishing',
 'vulnerability_exploited': 'Lack of phishing-resistant MFA, human error '
                            '(trust in fake IT support)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.