CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Passkey-themed phishing attacks lead to Microsoft 365 data theft

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7118

As cited

Copy frozen at (site build).

threat intel

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Threat actors affiliated with ShinyHunters, Helix, and other extortion gangs are deploying social engineering attacks themed around passkeys and single sign-on to compromise corporate Microsoft accounts and exfiltrate data from Microsoft 365 services. The attacks exploit trust in authentication mechanisms to gain unauthorized access to sensitive corporate data.

Why it matters: Any organization using Microsoft 365 is exposed to credential theft through passkey and SSO-themed phishing, putting email, documents, and collaboration data at risk; practitioners should reinforce user training on authentication-based social engineering and strengthen conditional access policies.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary