Passkey Phishing Campaign Targets Microsoft Cloud Accounts, Microsoft Warns
Microsoft discloses two campaigns: mass CEO-impersonation scams and passkey-themed social engineering aimed at hijacking cloud accounts and exfiltrating data.

Key Takeaways
- Microsoft disclosed two campaigns: one sending over 1 million CEO-impersonation scam emails, and another using passkey-themed social engineering to hijack cloud accounts.
- The passkey campaign targets Microsoft cloud accounts with the goal of data exfiltration.
- No CVE or patch is available; mitigation relies on phishing-resistant MFA and user awareness.
- Threat actors are abusing third-party email infrastructure to bypass traditional email security.
- Organizations should monitor for anomalous sign-ins and educate users about passkey phishing.
Quick answers
- What happened?
- Microsoft has revealed two active campaigns: one blasting over a million CEO-impersonation scam emails via third-party infrastructure, and another using passkey-themed social engineering to breach Microsoft cloud accounts and steal data. No CVE or patch is available; mitigation focuses on phishing-resistant MFA and user awareness.
- Which products are affected?
- Microsoft Cloud
- What should defenders do?
- Enable phishing-resistant MFA (e.g., FIDO2 security keys), educate users about passkey phishing, monitor for anomalous sign-ins, and implement email filtering to block CEO impersonation scams.
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to send financial fraud scam messages and using passkey-themed social engineering to breach cloud environments.
The first campaign involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers. These emails likely aimed to trick recipients into performing financial actions, such as wire transfers or payment changes, exploiting the authority of executive roles.
The second campaign uses passkey-themed social engineering to hijack Microsoft cloud accounts and exfiltrate data. While passkeys are generally considered more secure than passwords, attackers are leveraging user unfamiliarity with the technology to trick victims into approving authentication prompts or revealing credentials. The exact method of the social engineering is not detailed, but it likely involves fake notifications or phishing pages that mimic passkey authentication flows.
Microsoft has not attributed the campaigns to specific threat actors, and no technical exploit details have been provided. The disclosure, published by The Hacker News on September 13, 2026, highlights the evolving tactics of attackers who are adapting to new authentication technologies.
Organizations using Microsoft cloud services should be vigilant for unusual sign-in attempts and educate users about passkey-related phishing. Enabling phishing-resistant MFA, such as FIDO2 security keys, and monitoring for anomalous authentication patterns are recommended defensive measures.
Security Details
The campaigns abuse third-party email delivery infrastructure to send mass scam emails and use passkey-themed social engineering to trick users into approving authentication prompts or revealing credentials. The exact technical details of the passkey attack are not disclosed, but it likely involves fake passkey notifications or phishing pages. No CVE is associated.
Affected products
Microsoft Cloud
Mitigation
Enable phishing-resistant MFA (e.g., FIDO2 security keys), educate users about passkey phishing, monitor for anomalous sign-ins, and implement email filtering to block CEO impersonation scams.
Sources
The Hacker News
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Sep 13, 2026 · 10:11
Original link
Related Security News

NeedyMantis Malware Used for Long-Term Persistence in Targeted Intrusions
Microsoft has identified a malware family named NeedyMantis being used by threat actors to maintain long-term, unauthorized access to already-breached networks. The malware has been observed in targeted intrusions across a range of sectors, including telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors. Activity has been tracked since at least 2023 and remains ongoing.




