ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign
Campaign
Summary
Hide ▲
Show ▼
A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 365 data and connected cloud access across multiple organizations. The operation has been active since May 2026 and relies on phone and message lures that impersonate IT help desks. Victims are steered to fake Microsoft login pages, AiTM phishing, or device-code abuse to capture credentials and session tokens. Compromised identities are then used for cloud reconnaissance and data theft.
Related Happenings
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor Meta
H score40
First: 04.08.2026 20:27
Last: 04.08.2026 20:27
Sources 1
About this happening:
Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor MetaAbout this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
Campaign
H score34
First: 29.07.2026 20:54
Last: 29.07.2026 20:54
Sources 1
About this happening:
The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...
ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
CampaignAbout this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor Meta
H score36
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor MetaAbout this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Helix vishing and SharePoint data-extortion campaign
Campaign
H score38
First: 09.07.2026 20:08
Last: 09.07.2026 20:08
Sources 1
About this happening:
The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Helix vishing and SharePoint data-extortion campaign
CampaignAbout this happening: The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Timeline
-
11.09.2026 20:26 2 articles · 1h ago
ShinyHunters- and Helix-linked passkey phishing targets Microsoft 365 accounts
Initial DisclosureMicrosoft says threat actors linked to ShinyHunters, Helix, Storm-3121, and Storm-3032 are using passkey- and single sign-on-themed social engineering against corporate Microsoft accounts, steering employees to fake Microsoft login pages or device-code prompts to capture credentials and session tokens. After compromise, the attackers use Microsoft Graph for reconnaissance, add MFA methods they control, and collect data from Microsoft 365 resources including SharePoint Online, OneDrive for Business, Outlook Web, and Microsoft Exchange Online.
Show sources
- Passkey-themed phishing attacks lead to Microsoft 365 data theft — www.bleepingcomputer.com — 11.09.2026 20:26
- Passkey-themed phishing attacks lead to Microsoft 365 data theft — www.bleepingcomputer.com — 11.09.2026 20:26