CyberSecurity News
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
AI summary
Microsoft has revealed details of two campaigns where attackers are exploiting third-party email infrastructure to send financial fraud scam messages. The attackers are also using social engineering tactics related to passkeys to breach cloud environments. One of the campaigns involved sending over a million scam emails between August 3 and 5, 2026, where the attackers posed as chief executive officers. The goal of these campaigns is to hijack Microsoft cloud accounts and exfiltrate data. The attackers are using passkey-themed phishing to trick victims into divulging sensitive information. The campaigns highlight the use of sophisticated social engineering tactics by threat actors to target cloud environments.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

