// 1 CVE IN THE LAST 24H
Microsoft Security Research disclosed two threat actor campaigns exploiting passkey-themed social engineering to breach cloud environments. Attackers use vishing calls to personal phones, spoofed login portals, and device-code phishing to gain initial access, then register attacker-controlled MFA methods for persistence. Data exfiltration leverages Microsoft Graph API across SharePoint, OneDrive, and Exchange Online at rates designed to evade detection thresholds. Microsoft attributes initial access to Storm-3121 (linked to ShinyHunters/Falcon) and Storm-3032 (aka UNC6671/Helix), with infrastructure overlaps suggesting shared tradecraft or affiliate networks.

Microsoft Security Research disclosed on September 10, 2026, two threat actor campaigns that exploit third-party email infrastructure and passkey-themed social engineering to compromise Microsoft 365 accounts and breach cloud environments. The primary campaign, active since May 2026, does not attack passkeys as a technology: it exploits confusion around the passwordless transition as a social engineering surface, tricking victims into believing they must "update" a system they often have not yet adopted. The result is initial access that bypasses traditional MFA defenses and expands through abuse of legitimate APIs, making detection particularly insidious.

Key Takeaways
  • Attackers call or SMS employees' personal numbers impersonating IT help desk, using passkey, MFA, or SSO update pretexts.
  • Victims are redirected to spoofed sites mimicking the Microsoft login experience to funnel them into AitM or device-code authentication flows.
  • After initial access, attackers register MFA methods under their control (phone number, authenticator app, software OTP) for persistence.
  • Data exfiltration occurs via Microsoft Graph API at high frequency across SharePoint Online, OneDrive for Business, and Exchange Online, with a self-imposed limit of fewer than 1,000 files or emails per hour to blend into legitimate traffic.

Passkey Vishing: How the Compromise Flow Works

The initial mechanism is voice phishing, or vishing, with a thematic twist. According to Microsoft Security Research, attackers contact employees directly on their personal phone numbers, impersonating the internal IT department or an external help desk. The pretext is always the same urgency: the organization is migrating to passkeys, multi-factor authentication needs updating, or there is a single sign-on issue requiring immediate verification.

The targeting precision is striking. As Microsoft documented: "The actor appears to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms." Attackers know names, roles, corporate hierarchies: they do not spray and pray, but build credible narratives for each victim.

From there, the victim is pushed to a spoofed site. Attacker-registered domains follow deliberate patterns: subdomains incorporating the target company name on a generic passkey, SSO, or identity verification theme. BleepingComputer documented examples such as company-name.secure-passkey[.]com, passkeyhelpdesk[.]com, setupmypasskey[.]com, integratedsso[.]com. Once on the site, the victim is guided through two possible flows: an AitM proxy that intercepts credentials and session tokens, or a device-code flow where the user enters a code on the legitimate microsoft.com/devicelogin, granting the attacker session access.

The passkey is merely a pretext throughout. As Microsoft clarified, cited by BleepingComputer: "while the lures frequently revolve around passkeys, the attackers are not attempting to enroll a passkey." The technology is not the target; the transition moment is exploited, the comprehension gap between what users hear at conferences and what they actually use in their daily workflow.

MFA Persistence: When Defense Becomes the Weak Point

Once initial access is obtained, attackers do not move laterally with exploits or endpoint malware. They operate within the compromised identity perimeter, exploiting the Microsoft 365 tenant's own features. The first operation is enrollment of new authentication methods under attacker control: an alternate phone number, an authenticator app on their own device, a software OTP token.

This persistence mechanism is particularly effective because it makes the compromise resistant to partial countermeasures. If the victim notices anomalous access and changes their password, the attacker can still re-enter via the added MFA method. If an administrator resets the password without checking registered authentication methods, the backdoor remains active. Microsoft documented anomalous access to Microsoft Office Home from unmanaged devices, followed by expansion to SharePoint and OneDrive via Graph API, with active sessions lasting approximately one hour accessing multiple connected applications.

Device-code phishing in particular amplifies the impact surface. According to BleepingComputer, the compromised flow grants access not only to Microsoft 365 resources but to all connected SSO applications: Salesforce, Google Workspace, Dropbox, Adobe, SAP, Slack, Zendesk, Atlassian. A single tricked credential becomes a key to an extended corporate ecosystem.

Graph API Abuse: The Blind Spot in Cloud Detection

The exfiltration phase reveals the true structural problem of this campaign. Attackers do not use anomalous file transfer tools, do not generate traffic to known suspicious IPs, do not install malware. They use Microsoft Graph API, the same interface legitimate applications use to read email, access SharePoint documents, sync OneDrive files.

"The attack underscores a critical detection challenge: Microsoft Graph abuse rarely appears suspicious when viewed through a single API call" — Microsoft Security Research

Microsoft observed high-volume Graph activity across three core services: SharePoint Online, OneDrive for Business, and Exchange Online, all accessible via REST API. The operational pattern includes deliberate IP infrastructure rotation between authentication, reconnaissance, and exfiltration, with overall operation duration ranging from several hours to several days. Attackers self-limit to fewer than 1,000 files or emails per hour, a rate that does not trigger traditional anomaly detection thresholds.

Automation is evident. BleepingComputer detected python-httpx user agents in exfiltration calls, indicating custom scripts rather than manual interactivity. Preliminary reconnaissance via Graph API is extensive: users, groups, permissions, resources, accessible content. Attackers map the environment before selecting exfiltration targets, operating with the patience of an insider threat rather than the haste of traditional ransomware.

Microsoft emphasized the methodological implication: "This attack serves as a strong example of why Graph activity must be assessed holistically, with emphasis on behavioral progression and cross-event correlation rather than individual API requests in isolation." The challenge is not technical in the sense of signatures or IOCs: it is analytical, requiring correlation between authentication, MFA enrollment, resource access patterns, and temporal sequence of API calls.

Who Is Behind It: Storm-3121, Storm-3032, and the Shadow of UNC6671

Microsoft attributes the initial access activity to two threat actors: Storm-3121, associated with the ShinyHunters collective and the Falcon brand, and Storm-3032, also known as UNC6671 or Helix. The "Storm" designation indicates emerging groups or those undergoing consolidated attribution in Microsoft's taxonomy; the overlap with UNC6671 suggests shared tradecraft or a possible affiliate network rather than a unitary structure.

UNC6671 is a previously documented entity for vishing campaigns with credential harvesting panels on generic passkey-themed domains, with target-specific subdomains. Microsoft detected infrastructure overlaps between domains used in this campaign and the phishing apparatus previously associated with UNC6671, though no evidence definitively links Storm-3032 to the historical entity at this time. The uncertainty remains: unitary group, affiliate network, or shared infrastructure among multiple crews is undocumented in the brief.

An important operational distinction is worth noting. In the same September 10, 2026 disclosure, Microsoft also documented a distinct first campaign, active August 3–5, 2026: a CEO impersonation operation with ACH fraud that generated approximately 1 million fraudulent emails. That campaign differs in initial vector (mass email, not targeted vishing), objective (ACH fraud, not cloud data exfiltration), and likely actors. Sources do not clarify whether the generative AI use documented in the first campaign extends to the passkey vishing campaign: this remains an open question.

What to Do Now

The defensive response requires realignment on three fronts, all derived from facts documented by Microsoft and BleepingComputer.

First: anti-phishing training must evolve beyond the "don't click suspicious links" mantra. When the attack begins with a phone call to a personal number, no link has been clicked yet. Awareness must include independent verification: contact the IT department through a known channel, never use references provided by the caller.

Second: post-authentication controls on registered MFA methods must become standard operating procedure. Periodic review of devices and methods associated with accounts, with alerts on enrollment of new authenticators or non-preauthorized phone numbers. Password reset without MFA method verification is insufficient.

Third: Microsoft Graph API monitoring must shift from isolated thresholds to sequential behavioral analysis. Correlate anomalous authentication, directory service access, user/group reconnaissance, and massive access to SharePoint/OneDrive/Exchange within the same time window. Individual API calls appear legitimate; the behavioral progression reveals the attack.

Fourth: accelerating the transition to phishing-resistant MFA, particularly FIDO2 security keys, reduces vulnerability to AitM and device-code flows that bypass push notifications, SMS, and TOTP. The technology exists; the gap is organizational and deployment.

The Transition Paradox: When the Solution Becomes the Pretext

This campaign inverts traditional credential phishing logic. It is not an attack on the password: it is an attack on the moment the organization seeks to eliminate the password. Attackers do not compromise passkeys, which remain more secure than traditional credentials; they compromise the migration confusion, the communicative urgency, the pressure to be "compliant" with a new IT policy.

The cybersecurity industry has spent years educating users to recognize suspicious emails about passkeys. Now it must educate them to recognize who calls them to talk about passkeys. The attack surface shifts from asynchronous to synchronous channels, from text to voice, from link to dialogue. Defenses must follow the same shift, or the passwordless transition risks becoming the period of maximum exposure, not maximum security.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. thehackernews.com
  2. bleepingcomputer.com
  3. darkreading.com
  4. cyberscoop.com
  5. cyberpress.org
  6. microsoft.com
  7. thehackernews.uk