Microsoft passkey social engineering campaign targets cloud data exfiltration
Microsoft Security Research has identified a sophisticated social engineering campaign targeting cloud identities using passkey-themed lures. The attackers, including groups like Storm-3121, leverage Microsoft Graph API to conduct reconnaissance and exfiltrate data from SharePoint, OneDrive, and Exchange Online.
Key Takeaways
- Attackers use adversary-in-the-middle (AiTM) and device-code flows to compromise sessions, often starting with a phone call or SMS.
- Threat actors register malicious subdomains like 'company-name.secure-passkey.com' to establish credibility during the initial access phase.
- Persistence is maintained by registering unauthorized MFA methods, such as new phone numbers or software-based OTP tokens, under attacker control.
- Automated collection tools, including the python-httpx user agent, are used to systematically retrieve up to 1,000 files per hour from cloud workloads.
Why It Matters
This campaign demonstrates how attackers are weaponizing the industry-wide shift toward passkeys by using them as psychological lures to bypass traditional MFA. For streaming platforms and media enterprises, the systematic abuse of the Microsoft Graph API for reconnaissance means that standard API calls can mask large-scale data theft if not monitored holistically. The transition from identity compromise to high-volume exfiltration in SharePoint and OneDrive highlights a critical vulnerability in how cloud-based production and distribution workflows are secured. Organizations must now prioritize phishing-resistant FIDO2 credentials and strict conditional access to prevent automated scripts from traversing sensitive internal repositories. Watch for increased adoption of Graph activity logging as a baseline requirement for enterprise security posture.
Additional Context
Microsoft's broader threat intelligence apparatus has been tracking Storm-3121 as part of a wider pattern of identity-focused attacks against cloud tenants. In early 2026, Microsoft's Defender team published guidance on how threat actors abuse OAuth consent grants to gain persistent access to Microsoft 365 environments, a technique that shares the same Graph API reconnaissance chain observed in the Storm-3121 campaign. The overlap signals that passkey-themed lures are not isolated phishing experiments but part of a maturing playbook where initial access brokers hand off compromised tokens to specialized exfiltration crews. Microsoft Defender for Cloud Apps has since added detection policies specifically flagging anomalous Graph API enumeration patterns, according to Microsoft's updated Defender for Cloud Apps documentation released in July 2026.
Read full article at microsoft.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source