News

Microsoft tracks passkey lures into Microsoft 365 cloud theft

Microsoft Security Research, in a 9 September 2026 blog, tracks passkey-themed helpdesk lures since May 2026 that lead to Microsoft 365 Graph reconnaissance and theft paced under 1,000 files or emails per hour. Named actors include Storm-3121 and Storm-3032.

Microsoft tracks passkey lures into Microsoft 365 cloud theft

Microsoft Security Research published a 9 September 2026 threat blog on passkey-themed social engineering that leads to identity and Microsoft 365 cloud compromise. The team has tracked the pattern since May 2026: unusual sign-ins, attacker-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs.

This is a Microsoft Security Research blog. It is not a CVE, not a CISA Known Exploited Vulnerabilities listing, and not a product launch.

Initial access often starts with a call or SMS on the employee's personal phone from someone claiming to be IT helpdesk, pushing an urgent passkey, MFA, or SSO update. The passkey story is often a pretext. The real path is adversary-in-the-middle phishing or a device-code flow that captures credentials and session tokens, or authorizes an attacker-controlled client.

Because the first contact lands on a personal phone, Help Net Security notes there is little endpoint telemetry. In several reviewed cases, the earliest evidence was the employee remembering the call or text.

After access, the actors enroll their own MFA (phone, authenticator, or software OTP) so they can stay in after the first stolen session dies. They then use Microsoft Graph to enumerate users, groups, roles, apps, SharePoint, OneDrive, and mail. Collection is measured: fewer than 1,000 files or emails accessed in any one-hour period, over hours to days.

Microsoft Threat Intelligence attributes the initial access to a range of actors, including Storm-3121 (which feeds ShinyHunters and Falcon extortion) and Storm-3032 (a BlackFile splinter now under the Helix banner).

Microsoft's own defenses include phishing-resistant MFA (FIDO2 passkeys, Windows Hello), Conditional Access that requires managed devices, blocking the device-code flow except where needed, enabling Graph activity logs, then revoking sessions and removing unauthorized authentication methods on compromise.

Related identity and cloud-theft tape includes Azure data advertised against Fortune 500 names, ChatGPT's sandbox cross-account leak, Mullvad's Android NAT-T VPN leak, and Check Point's PuzzleMask plain-prose bypass.

If you run Microsoft 365, hunt since May 2026 for new MFA methods plus Graph enumeration plus SharePoint, OneDrive, or mail pulls under about 1,000 items an hour, revoke sessions, strip unauthorized auth methods, and treat a passkey helpdesk call on a personal phone as the start of an identity incident.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free