Passkey Phishing Hijacks Microsoft Cloud Accounts

← Back to articles

Passkey Phishing Hijacks Microsoft Cloud Accounts

Microsoft confirmed that threat actors launched two coordinated campaigns this week, using compromised email services to send over a million fake CEO messages and exploiting “passkey” themed phishing to breach Microsoft cloud accounts and steal data.

The first wave targeted corporate executives by spoofing chief executive officers in emails sent between August 3 and August 5, 2026. Recipients received messages that appeared to come from their own CEOs, urging immediate financial actions. The emails were distributed through third‑party email delivery platforms, allowing the attackers to reach a massive audience quickly.

In the second campaign, the same groups leveraged the growing popularity of passkey authentication to trick users into revealing credentials. They crafted phishing emails that mimicked legitimate Microsoft communications about passkey setup or recovery, prompting victims to click malicious links and enter their authentication details on counterfeit login pages.

Businesses that rely on Microsoft Azure and Office 365 services are the primary victims, but any user who receives a passkey‑related email from Microsoft could be exposed. The attackers used the stolen credentials to log into cloud environments, exfiltrate files, and potentially install additional malware.

Microsoft’s investigation shows that the attackers used legitimate email infrastructure to avoid detection, and the passkey phishing relied on convincing design that mirrored official Microsoft branding. This underscores how quickly new security features can become a lure for fraudsters.

To protect yourself, verify any unexpected request for financial action by contacting the sender through a known channel, not the reply button. When receiving passkey or authentication emails, check the sender’s address carefully and hover over links to see the true destination. Use multi‑factor authentication that includes a separate verification method, and consider using the free email‑header analysis tool available at ComputerScams.com to confirm the source of suspicious messages.

If you suspect your Microsoft cloud account has been compromised, reset your password immediately, revoke all active sessions, and review recent sign‑in activity. Enabling conditional access policies that restrict logins to known locations can also limit exposure.

A practical step you can take right now is to enable the Microsoft Authenticator app for every account that supports it, adding an extra layer beyond passkeys alone.

Source: Read the original report

Scroll to Top