Passkey-themed phishing attacks lead to Microsoft 365 data theft
by Lawrence Abrams · BleepingComputerMicrosoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.
The activity has been observed since May 2026 and begins with the attackers researching targeted organizations and employees before calling or messaging victims while impersonating corporate IT help desks.
The attackers tell employees that they must urgently update a passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to avoid losing access to corporate systems.
Victims are then directed to phishing sites designed to resemble legitimate Microsoft login pages, with links sometimes sent through SMS messages to employees' personal phones.
Microsoft says that while the lures frequently revolve around passkeys, the attackers are not attempting to enroll a passkey.
Instead, the passkey lures are used to trick targeted employees into signing in to adversary-in-the-middle (AiTM) phishing sites or using device-code authentication flows.
AiTM attacks allow the threat actors to capture credentials and session tokens. Device code phishing tricks victims into authorizing access to their account via an attacker-controlled client using Microsoft's legitimate authentication pages.
Microsoft says the attackers conduct extensive research before targeting employees.
"The actor appears to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms," explains Microsoft.
The threat actors also register phishing domains that combine company names with words related to passkeys, SSO, key synchronization, account setup, and identity verification.
Some examples seen by Microsoft include: passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, oktasession[.]com, keysyncos[.]com, and oskeysync[.]com.
The attackers commonly place the victim company's name in a subdomain, such as company-name.secure-passkey[.]com, to make the phishing portal appear more convincing.
Microsoft attributes the initial-access activity to multiple threat actors operating in the same extortion ecosystem, including groups it tracks as Storm-3121 and Storm-3032.
Storm-3121 is associated with ShinyHunters and Falcon extortion, while Storm-3032 is believed to be tied to BlackFile extortion group members that now work under the Helix name.
This activity overlaps with attacks previously documented by Google Threat Intelligence under the UNC6671 threat cluster.
Google previously reported that UNC6671 uses phone-based social engineering and passkey-themed phishing infrastructure to compromise corporate identities before accessing enterprise cloud environments.
Google has also linked UNC6671 activity to the same extortion gangs, including BlackFile, Helix, Falcon, Pink, and Redact.
Mapping the Microsoft cloud after compromise
Microsoft's new research gives a closer look at what happens inside Microsoft cloud environments after an account is compromised.
In one investigated attack, Microsoft observed a suspicious sign-in from an unmanaged device to a Microsoft 365 service identified in Entra logs as "OfficeHome."
OfficeHome is associated with the Office 365 portal's shared infrastructure, including Office applications accessed through a browser.
After completing MFA, Microsoft says the attacker established a valid session and began checking what resources the compromised account could access.
Within minutes, the session was used to access My Apps to see what applications are assigned to the account, My Profile for organizational information, Microsoft Approval Management, account-management interfaces, and My Sign-Ins.
The attacker then accessed SharePoint Online, Outlook Web, Microsoft 365 collaboration and search services, an internal business application, and authentication flows associated with virtual desktops.
Microsoft says the session remained active for approximately one hour while the attacker listed sensitive files and internal applications.
In another attack, the passkey social engineering attacks led to device-code phishing, where the victim was convinced to enter a supplied code into Microsoft's legitimate authentication page.
This issues an authentication token to the attacker-controlled OAuth application, allowing the threat actor to access the victim's account without completing another MFA challenge.
The attacker now has access to all of the user's resources and connected SSO applications, whether they be Microsoft 365, Salesforce, Google Workspace, Dropbox, Adobe, SAP, Slack, Zendesk, Atlassian, and many others.
In a third attack, the threat actor used previously compromised credentials for an account where it is believed an authenticator application had been registered days earlier.
Microsoft says the threat actors then performed reconnaissance using an automated Node.js system and Microsoft Graph.
After gaining access, the attackers often gain persistence by adding an MFA method they control.
Microsoft says the attackers register new phone numbers, authenticator applications, and software-based one-time password tokens with compromised identities.
This allows the threat actor to satisfy future MFA challenges without the victim's help, although Microsoft notes that the persistence does not survive a complete credential and session reset.
The attackers then use Microsoft Graph to enumerate the victim's cloud environment.
Microsoft saw Graph requests that enumerate:
- Organizations, licenses, and enabled services
- Users, groups, and group membership
- Directory roles and privileged accounts
- Registered authentication methods
- Applications and service principals
- OAuth permissions and application role assignments
- SharePoint sites, document libraries, folders, and files
- OneDrive resources
- Mail folders, messages, and attachments
Microsoft says Graph requests such as /users, /groups, or /sites are common in enterprise environments, so they may not raise alarms.
However, the activity becomes more suspicious when the same account, application, or access token rapidly moves across different resources, checks privileges and authentication settings, and then begins accessing email, attachments, files, or documents.
After reconnaissance, the attackers move into cloud data collection from Microsoft 365.
"Microsoft observed high-volume access and download activity targeting Microsoft SharePoint Online and Microsoft OneDrive for Business, with some intrusions extending into Microsoft Exchange Online through REST API-based access to email content," explained Microsoft.
"Across SharePoint and OneDrive, the activity generated significant volumes of FileAccessed and FileDownloaded events, indicating systematic retrieval of cloud-hosted documents and organizational data."
Microsoft says the activity appears automated, with connections using the python-httpx user agent during SharePoint and OneDrive access exfiltration.
The attackers also appear to avoid rapid "smash-and-grab" exfiltration to avoid detection.
Microsoft says the data theft instead lasts from a few hours to multiple days, with threat actors accessing fewer than 1,000 files or emails in a single hour to blend in with legitimate traffic.
Microsoft recommends looking for unusual sign-ins followed by new MFA registrations, Microsoft Graph reconnaissance, and suspicious access to SharePoint, OneDrive, or Exchange.
If an account is compromised, administrators should revoke active sessions and tokens, reset credentials, remove any authentication methods or mailbox rules added by the attackers, and require the user to re-register their authentication methods.
Microsoft also recommends using phishing-resistant MFA, limiting sensitive cloud resources to managed devices, and disabling device-code authentication when it is not needed.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.