Extortion Gangs Deploy Passkey‑Themed Phishing to Hijack Microsoft 365 Accounts
Microsoft has warned that criminal groups, including those associated with ShinyHunters and Helix, are running phishing campaigns that masquerade as passkey or single sign‑on (SSO) requests to infiltrate corporate Microsoft 365 environments.
The attacks exploit the growing popularity of password‑less authentication, using familiar language and visuals that suggest a legitimate security prompt. When a victim clicks the forged link, the malicious page harvests the user’s credentials or captures the passkey authentication token, granting the attacker access to the victim’s Microsoft account.
Once inside, threat actors can move laterally across the tenant, exfiltrating emails, documents, and other data stored in Exchange Online, SharePoint, and OneDrive. The stolen information is typically leveraged for extortion, with groups threatening to release confidential files unless a ransom is paid.
Microsoft’s security teams say the campaigns are part of a broader trend in which attackers adapt social‑engineering tactics to new authentication technologies. By framing the lure as a “passkey verification” or “SSO approval,” they increase the likelihood that employees will comply, especially as organizations encourage password‑less sign‑ins to reduce credential‑stuffing attacks.
Security experts advise organizations to reinforce user education, emphasizing that legitimate passkey or SSO prompts never request additional personal information or direct users to unfamiliar URLs. Deploying conditional access policies, enforcing multi‑factor authentication (MFA) for privileged accounts, and monitoring for anomalous sign‑in activity are also recommended defenses.
Microsoft has issued guidance for administrators to review recent sign‑in logs, reset compromised credentials, and enable advanced threat protection features. The company says it continues to investigate the scope of the intrusion and will work with affected customers to mitigate any further data loss.
Comments (0)
Be the first to comment.
Join the discussion