
highPhishing
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Microsoft has warned that threat actors linked to extortion gangs such as ShinyHunters and Helix are conducting passkey-themed phishing campaigns targeting corporate Microsoft 365 accounts. The attacks use social engineering to trick users into revealing passkey credentials or approving single sign-on prompts, resulting in data theft and account compromise. The campaign was reported on September 11, 2026, and affects corporate Microsoft accounts globally.
BleepingComputer1 min read