CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

September 13, 2026

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data Ravie LakshmananSep 13, 2026Cloud Security / Identity Security Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers (CEOs) of various target companies, aiming to persuade accounts payable departments at those firms to initiate Automated Clearing House (ACH) transfers for a supposed ServiceNow annual subscription. Evidence indicates that the operators behind the campaign have leveraged generative artificial intelligence (AI) to…