$ techbeacon▋
Phishing

Threat Actors Exploit Passkey Phishing and Third‑Party Email Relays to Compromise Microsoft Cloud Accounts

Threat Actors Exploit Passkey Phishing and Third‑Party Email Relays to Compromise Microsoft Cloud Accounts

Microsoft has warned that two coordinated campaigns are leveraging a blend of email‑relay abuse and passkey‑oriented social engineering to infiltrate corporate cloud environments and steal data. In the first operation, attackers hijacked third‑party email delivery platforms to flood targets with financial‑fraud scams, while a parallel effort used misleading references to "passkeys"—the password‑less authentication method promoted by major tech firms—to trick users into surrendering credentials that grant access to Microsoft 365 and Azure resources.

The abuse of third‑party email infrastructure allows threat actors to bypass many traditional spam filters, as messages appear to originate from legitimate service providers. Recipients receive polished solicitations promising quick returns on investments or urgent payment requests, prompting them to click malicious links or disclose payment details. Microsoft’s analysis indicates that the volume of such fraudulent mail has risen sharply, reflecting a broader trend of attackers exploiting trusted delivery channels to increase the credibility of their lures.

In the passkey‑phishing strand, the social‑engineering narrative centers on the growing adoption of biometric and cryptographic “passkeys” as a replacement for passwords. Attackers craft emails that claim to be from Microsoft or a partner organization, urging users to “verify” or “update” their passkey settings via a counterfeit portal. Once the victim enters their authentication token or provides a one‑time code, the adversary gains a foothold in the victim’s cloud tenant. From there, they can enumerate resources, copy files, and exfiltrate sensitive information without triggering standard anomaly detectors that focus on password‑based attacks.

Microsoft says the campaigns demonstrate how threat actors are adapting to emerging security technologies. By framing their lures around passkeys—a concept still unfamiliar to many end users—attackers exploit a knowledge gap, turning a security improvement into an attack vector. The company urges organizations to reinforce user education, enforce multi‑factor authentication that does not rely solely on passkey prompts, and monitor for anomalous activity in privileged accounts.

Security experts note that the incidents underscore the importance of scrutinizing email delivery pathways and applying strict DMARC, SPF, and DKIM policies to limit third‑party relay abuse. They also recommend that administrators enable conditional access policies that require additional verification when passkey enrollment or changes are initiated from unfamiliar locations. As the industry continues to transition toward password‑less authentication, Microsoft’s disclosure serves as a reminder that any new technology can be weaponized if users are not adequately informed and protective controls are not rigorously applied.

Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related