CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7159

As cited

Copy frozen at (site build).

threat intel

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft disclosed two campaigns in which threat actors sent over one million fraudulent emails between August 3 and 5, 2026, by impersonating chief executive officers and using passkey-themed social engineering to compromise cloud environments. Attackers leveraged third-party email delivery infrastructure to distribute the financial fraud scams and gain unauthorized access to victim accounts.

Why it matters: Organizations with Microsoft cloud environments face credential compromise via passkey phishing; practitioners should review email authentication controls, monitor for suspicious cloud access patterns, and brief users on social engineering tactics impersonating executives.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary