Find notable cyber news and cases, enriched with sources, timelines, and signals.

ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 365 data and connected cloud access across multiple organizations. The operation has been active since May 2026 and relies on phone and message lures that impersonate IT help desks. Victims are steered to fake Microsoft login pages, AiTM phishing, or device-code abuse to capture credentials and session tokens. Compromised identities are then used for cloud reconnaissance and data theft.

Related Happenings

Greatness PhaaS expands into device code phishing and integrated token-theft operations

Threat Actor Meta
H score40 First: 04.08.2026 20:27 Last: 04.08.2026 20:27 Sources 1

About this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...

ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations

Campaign
H score34 First: 29.07.2026 20:54 Last: 29.07.2026 20:54 Sources 1

About this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...

Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking

Threat Actor Meta
H score36 First: 13.07.2026 16:03 Last: 13.07.2026 16:03 Sources 1

About this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...

Helix vishing and SharePoint data-extortion campaign

Campaign
H score38 First: 09.07.2026 20:08 Last: 09.07.2026 20:08 Sources 1

About this happening: The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...

Forg365-ForgCookie alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score37 First: 09.07.2026 17:39 Last: 09.07.2026 17:39 Sources 1

About this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...

Timeline

  1. 11.09.2026 20:26 2 articles · 1h ago

    ShinyHunters- and Helix-linked passkey phishing targets Microsoft 365 accounts

    Initial Disclosure

    Microsoft says threat actors linked to ShinyHunters, Helix, Storm-3121, and Storm-3032 are using passkey- and single sign-on-themed social engineering against corporate Microsoft accounts, steering employees to fake Microsoft login pages or device-code prompts to capture credentials and session tokens. After compromise, the attackers use Microsoft Graph for reconnaissance, add MFA methods they control, and collect data from Microsoft 365 resources including SharePoint Online, OneDrive for Business, Outlook Web, and Microsoft Exchange Online.

    Show sources