Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft dual phishing campaigns using CEO impersonation and passkey lures

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

Microsoft disclosed two coordinated phishing campaigns that used third-party email delivery infrastructure and passkey-themed social engineering to target U.S. enterprise users, raising the risk of payment fraud and cloud account compromise. One wave sent over a million scam emails in August 2026 by impersonating CEOs and pushing fake ACH transfer requests. A separate operation active since May 2026 used counterfeit sign-in pages, AitM and device-code flows, and attacker-controlled MFA enrollment to seize Microsoft cloud accounts. The activity also enabled Graph API reconnaissance and data collection from SharePoint Online, OneDrive, and mailboxes.

Related Happenings

ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign

Campaign
H score34 First: 11.09.2026 20:26 Last: 11.09.2026 20:26 Sources 1

About this happening: A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...

High-volume Unicode-smuggling phishing campaign

Campaign
H score29 First: 04.09.2026 18:57 Last: 04.09.2026 18:57 Sources 1

About this happening: A high-volume phishing campaign is using invisible Unicode tag characters to split lure words and bypass email filters, pushing finance-themed emails at scale. The...

UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign

Campaign
H score16 First: 20.08.2026 22:59 Last: 20.08.2026 22:59 Sources 1

About this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...

Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026

Trend
H score30 First: 28.07.2026 16:00 Last: 28.07.2026 16:00 Sources 1

About this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...

BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign

Campaign
H score38 First: 24.07.2026 18:12 Last: 24.07.2026 18:12 Sources 1

About this happening: BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...

Timeline

  1. 13.09.2026 13:11 2 articles · 1h ago

    Microsoft details CEO impersonation fraud and passkey-themed cloud compromise

    Initial Disclosure

    Microsoft described two phishing campaigns affecting enterprise targets: one used third-party email delivery infrastructure to send over a million scam emails between August 3 and 5, 2026 by impersonating CEOs and pushing fake ACH transfers for a supposed ServiceNow annual subscription, while a separate operation active since May 2026 used passkey-themed social engineering to lure employees to counterfeit Microsoft sign-in pages, add attacker-controlled MFA methods, and collect data through Microsoft Graph, SharePoint Online, OneDrive, and mailbox access.

    Show sources