#1
The Hacker News
general
September 13, 2026 at 10:11 UTC
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
By [email protected] (The Hacker News)
AI Summary
Microsoft disclosed two active threat campaigns: one involving over one million scam emails sent between August 3–5, 2026, with attackers impersonating CEOs via third-party email infrastructure, and a second using passkey-themed social engineering to breach Microsoft cloud environments and exfiltrate data. Security practitioners should review cloud account protections and monitor for passkey-abuse phishing lures targeting enterprise tenants.
Relevance score: 82.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →