Microsoft dual phishing campaigns using CEO impersonation and passkey lures
Campaign
Summary
Hide ▲
Show ▼
Microsoft disclosed two coordinated phishing campaigns that used third-party email delivery infrastructure and passkey-themed social engineering to target U.S. enterprise users, raising the risk of payment fraud and cloud account compromise. One wave sent over a million scam emails in August 2026 by impersonating CEOs and pushing fake ACH transfer requests. A separate operation active since May 2026 used counterfeit sign-in pages, AitM and device-code flows, and attacker-controlled MFA enrollment to seize Microsoft cloud accounts. The activity also enabled Graph API reconnaissance and data collection from SharePoint Online, OneDrive, and mailboxes.
Related Happenings
ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign
Campaign
H score34
First: 11.09.2026 20:26
Last: 11.09.2026 20:26
Sources 1
About this happening:
A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...
ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign
CampaignAbout this happening: A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...
High-volume Unicode-smuggling phishing campaign
Campaign
H score29
First: 04.09.2026 18:57
Last: 04.09.2026 18:57
Sources 1
About this happening:
A high-volume phishing campaign is using invisible Unicode tag characters to split lure words and bypass email filters, pushing finance-themed emails at scale. The...
High-volume Unicode-smuggling phishing campaign
CampaignAbout this happening: A high-volume phishing campaign is using invisible Unicode tag characters to split lure words and bypass email filters, pushing finance-themed emails at scale. The...
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
Campaign
H score16
First: 20.08.2026 22:59
Last: 20.08.2026 22:59
Sources 1
About this happening:
A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
CampaignAbout this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
Trend
H score30
First: 28.07.2026 16:00
Last: 28.07.2026 16:00
Sources 1
About this happening:
Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
TrendAbout this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
Campaign
H score38
First: 24.07.2026 18:12
Last: 24.07.2026 18:12
Sources 1
About this happening:
BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
CampaignAbout this happening: BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
Timeline
-
13.09.2026 13:11 2 articles · 1h ago
Microsoft details CEO impersonation fraud and passkey-themed cloud compromise
Initial DisclosureMicrosoft described two phishing campaigns affecting enterprise targets: one used third-party email delivery infrastructure to send over a million scam emails between August 3 and 5, 2026 by impersonating CEOs and pushing fake ACH transfers for a supposed ServiceNow annual subscription, while a separate operation active since May 2026 used passkey-themed social engineering to lure employees to counterfeit Microsoft sign-in pages, add attacker-controlled MFA methods, and collect data through Microsoft Graph, SharePoint Online, OneDrive, and mailbox access.
Show sources
- Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data — thehackernews.com — 13.09.2026 13:11
- Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data — thehackernews.com — 13.09.2026 13:11