ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign
Campaign
Updated: 11.09.2026 20:26
· First: 11.09.2026 20:26
· 📰 1 src / 1 articles
· H score: 34
A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 365 data and connected cloud access across multiple organizations. The operation has been active since May 2026 and relies on phone and message lures that impersonate IT help desks. Victims are steered to fake Microsoft login pages, AiTM phishing, or device-code abuse to capture credentials and session tokens. Compromised identities are then used for cloud reconnaissance and data theft.