Posted in

Microsoft Warns of CEO Fraud and Passkey Phishing Attacks Targeting Cloud Accounts

Microsoft has disclosed details of two cybercrime campaigns targeting organizations with increasingly sophisticated social engineering techniques.

One campaign used CEO impersonation, fake invoices, and trusted email infrastructure to trick finance teams into sending fraudulent ACH payments. The second campaign used passkey- and MFA-themed social engineering to compromise Microsoft cloud accounts and establish persistent access.

According to Microsoft, the two campaigns demonstrate how threat actors are combining social engineering, identity attacks, automation, and legitimate cloud services to bypass traditional security defenses.

More Than 1 Million Fake Payment Emails Sent

The first campaign involved more than one million fraudulent emails sent between August 3 and August 5, 2026.

The messages impersonated CEOs and other senior executives at targeted companies and were designed to convince accounts payable employees to authorize Automated Clearing House (ACH) payments for a supposedly legitimate annual ServiceNow subscription.

The campaign primarily targeted enterprise organizations in the United States, including businesses in:

  • IT services
  • Consumer goods
  • Real estate
  • Discrete manufacturing

Microsoft said the attackers used generative AI to help create convincing email templates and customize messages for individual recipients.

The campaign combined several familiar fraud techniques into a single narrative, including executive impersonation, vendor branding, fake invoices, and fabricated email conversations.

“Unlike traditional invoice scams that rely on a single social engineering lure, this campaign layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism.”

Attackers Impersonated Company Executives

The fraudulent emails contained what appeared to be an executive’s approval of a payment request.

Attackers researched organizations to identify CEOs, CFOs, presidents, and other senior executives. They then inserted the names and email addresses of those individuals into message signatures to make the requests appear authentic.

The emails also contained forged conversations and fabricated invoices designed to create the appearance of an ongoing business transaction.

To further reinforce the deception, attackers registered domains that mimicked legitimate companies and services.

Examples identified by Microsoft include:

  • service-nowinc[.]com
  • domainlify[.]net

The combination of a familiar executive name, a recognizable vendor, an apparently approved invoice, and a fabricated email history was intended to convince finance personnel that the payment was legitimate.

Passkey-Themed Phishing Used to Compromise Cloud Accounts

Microsoft’s second investigation involves a separate campaign targeting cloud identities.

The activity has been observed since May 2026 and involves suspicious account sign-ins followed by attackers registering their own authentication methods.

Once access is obtained, attackers conduct extensive activity across Microsoft cloud services, including Microsoft Graph, SharePoint, OneDrive, and Exchange Online.

Microsoft described the activity as consistent with automated collection from compromised cloud identities using proxy-linked infrastructure.

Fake IT Help Desk Calls Target Employees

The attacks commonly begin with identity-focused social engineering.

Threat actors contact employees through personal phone numbers or messaging channels while pretending to work for the organization’s IT help desk.

The attacker then claims that the employee needs to urgently update a passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to prevent an account or service disruption.

Victims are subsequently directed to fraudulent websites designed to resemble legitimate Microsoft login pages.

The ultimate goal is to convince the employee to complete an adversary-in-the-middle (AiTM) authentication process or a device-code authentication flow.

Rather than simply stealing a password, attackers can use these techniques to obtain authenticated access or trick the victim into authorizing the attacker’s session.

Attackers Conduct Extensive Pre-Attack Research

Microsoft said the threat actors appear to conduct significant reconnaissance before contacting their targets.

They likely gather information about employees, job responsibilities, and organizational structures from publicly available sources, including professional networking and social media platforms.

In some cases, attackers have also used previously compromised accounts to distribute similar passkey-themed messages through Microsoft Teams.

The attackers have registered numerous domains designed around themes such as passkeys, SSO enrollment, account activation, and identity verification.

Examples include:

  • passkeyhelpdesk[.]com
  • secure-passkey[.]com
  • setupmypasskey[.]com
  • add-passkey[.]com
  • integratedsso[.]com
  • oktasession[.]com
  • syncmykey[.]com
  • portalsetuphub[.]com

Researchers say these domains may also use the targeted company’s name as a subdomain, creating URLs that appear customized for the victim organization.

Links to Known Cybercrime Activity

The tactics observed by Microsoft overlap with activity associated with several cybercrime clusters tracked by the security community, including Cordial Spider, O-UNC-045, PREY-0058, and UNC6671.

The groups are believed to operate within a broader cybercrime ecosystem that includes phishing infrastructure, voice-phishing operations, extortion campaigns, and shared tooling.

Google-owned Mandiant previously noted that UNC6671 uses credential-harvesting infrastructure hosted on generic domains designed around passkeys, with victim-specific subdomains used to support targeted voice-phishing campaigns.

The precise relationships between the various groups remain unclear. Security researchers believe some of the overlap could stem from affiliates sharing initial-access techniques, commercially available phishing panels, voice-phishing services, or infrastructure.

Microsoft has separately attributed observed initial-access activity to multiple threat actors, including Storm-3121 and Storm-3032.

Microsoft identifies Storm-3032 as UNC6671, while Storm-3121 has been associated with initial-access activity leading to extortion operations involving groups such as ShinyHunters and Falcon.

Attackers Add Their Own MFA Methods

One of the most concerning aspects of the campaign is what happens after an account is compromised.

Instead of relying exclusively on stolen credentials, attackers attempt to establish a more permanent foothold by registering their own authentication method.

This can include:

  • A new phone number
  • An authenticator application
  • A software-based one-time password (OTP) token

Microsoft said this allows attackers to authenticate independently after the initial compromise.

If legitimate credentials remain valid and existing sessions have not been revoked, the attacker-controlled MFA method can provide continued access even after the original phishing event.

“Following initial access, the actor’s first objective was to transform a temporary compromise into a persistent foothold.”

Cloud Accounts Become a Gateway to Sensitive Data

After establishing persistence, the attackers can use the compromised identity to conduct extensive reconnaissance across the victim’s Microsoft cloud environment.

Microsoft observed attackers using Microsoft Graph to:

  • Enumerate users and groups
  • Identify permissions and resources
  • Search for privileged accounts and service identities
  • Investigate accessible files and internal services
  • Collect mailbox messages, folders, and attachment metadata
  • Download large volumes of data from SharePoint and OneDrive
  • Access Exchange Online in some cases
  • Exfiltrate files and email content over several hours or days

In one incident, Microsoft observed an unusual sign-in to Microsoft Office Home from an unmanaged device. The attackers then used Microsoft Graph to expand their access to SharePoint Online and OneDrive and search for sensitive information.

Another attack used a passkey lure to initiate a device-code phishing attack, allowing the threat actor to gain control of an account without directly stealing the user’s password or browser cookies.

Attackers Rotate Infrastructure to Evade Detection

The campaign also demonstrates an effort to make detection more difficult.

Threat actors reportedly use different infrastructure and IP addresses for separate stages of the attack, including authentication, reconnaissance, and data exfiltration.

This separation can make traditional network-based detection more challenging because individual events may not immediately appear connected.

Microsoft emphasized that defenders should therefore look for behavioral patterns across multiple events, rather than treating individual API requests as isolated incidents.

“Microsoft Graph abuse rarely appears suspicious when viewed through a single API call.”

Instead, security teams should correlate suspicious authentication events with subsequent MFA registration, Graph API reconnaissance, mailbox access, SharePoint downloads, and unusual data-transfer activity.

Why These Attacks Matter

The two campaigns highlight a broader shift in enterprise cyberattacks.

Attackers are increasingly moving beyond conventional password phishing and instead targeting identity workflows and trusted business processes.

In the first campaign, attackers exploited the trust employees place in senior executives and established vendors.

In the second, they exploited employees’ expectations around passkeys, MFA, SSO, and IT support.

The use of legitimate cloud APIs and authentication mechanisms makes these attacks particularly challenging because many individual actions can appear normal when examined separately.

For organizations, the lesson is clear: protecting cloud environments requires more than strong passwords or MFA. Security teams must monitor authentication changes, newly registered MFA methods, unusual API activity, abnormal downloads, and suspicious sequences of behavior across the entire identity lifecycle.

Organizations should also ensure employees know that legitimate IT teams should never pressure them into approving unexpected authentication requests or entering credentials into unfamiliar websites.

Leave a Reply

Your email address will not be published. Required fields are marked *