As cited
Copy frozen at (site build).
threat intel
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Threat actors affiliated with ShinyHunters, Helix, and other extortion gangs are deploying social engineering attacks themed around passkeys and single sign-on to compromise corporate Microsoft accounts and exfiltrate data from Microsoft 365 services. The attacks exploit trust in authentication mechanisms to gain unauthorized access to sensitive corporate data.
Why it matters: Any organization using Microsoft 365 is exposed to credential theft through passkey and SSO-themed phishing, putting email, documents, and collaboration data at risk; practitioners should reinforce user training on authentication-based social engineering and strengthen conditional access policies.
- Source published
- First seen by Cybersecurity Tracker