$ techbeacon▋
Ransomware

Extortion Gangs Deploy Passkey‑Themed Phishing to Hijack Microsoft 365 Accounts

Extortion Gangs Deploy Passkey‑Themed Phishing to Hijack Microsoft 365 Accounts

Microsoft has warned that criminal groups, including those associated with ShinyHunters and Helix, are running phishing campaigns that masquerade as passkey or single sign‑on (SSO) requests to infiltrate corporate Microsoft 365 environments.

The attacks exploit the growing popularity of password‑less authentication, using familiar language and visuals that suggest a legitimate security prompt. When a victim clicks the forged link, the malicious page harvests the user’s credentials or captures the passkey authentication token, granting the attacker access to the victim’s Microsoft account.

Once inside, threat actors can move laterally across the tenant, exfiltrating emails, documents, and other data stored in Exchange Online, SharePoint, and OneDrive. The stolen information is typically leveraged for extortion, with groups threatening to release confidential files unless a ransom is paid.

Microsoft’s security teams say the campaigns are part of a broader trend in which attackers adapt social‑engineering tactics to new authentication technologies. By framing the lure as a “passkey verification” or “SSO approval,” they increase the likelihood that employees will comply, especially as organizations encourage password‑less sign‑ins to reduce credential‑stuffing attacks.

Security experts advise organizations to reinforce user education, emphasizing that legitimate passkey or SSO prompts never request additional personal information or direct users to unfamiliar URLs. Deploying conditional access policies, enforcing multi‑factor authentication (MFA) for privileged accounts, and monitoring for anomalous sign‑in activity are also recommended defenses.

Microsoft has issued guidance for administrators to review recent sign‑in logs, reset compromised credentials, and enable advanced threat protection features. The company says it continues to investigate the scope of the intrusion and will work with affected customers to mitigate any further data loss.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related