Microsoft Warns of Fake Passkey and CEO-Impersonation Phishing Campaigns Targeting Corporate Accounts
Microsoft has disclosed two social engineering campaigns observed in 2026 that targeted corporate payment workflows and Microsoft cloud identities. The activity combines CEO impersonation, fraudulent invoices and ACH payment requests with phone and SMS phishing built around urgent passkey, MFA and SSO updates.
Key Details:
Between August 3 and August 5, 2026, more than one million fraudulent emails targeted corporate users in the United States. Attackers impersonated company CEOs and asked accounting and payment teams to initiate ACH transfers for a fake annual ServiceNow subscription.
The emails included fabricated invoices, executive signatures and fake approval threads. Microsoft found evidence suggesting that generative AI was used to prepare and customize phishing email content for individual recipients.
In a second campaign tracked since May 2026, employees were contacted by phone, SMS and, in some cases, Microsoft Teams. Attackers posed as IT help desk staff and claimed that passkey, MFA or SSO settings urgently needed to be updated.
Victims were directed to websites that imitated legitimate Microsoft sign-in pages. Attackers used adversary-in-the-middle (AitM) flows and device-code authentication abuse to obtain access to corporate accounts.
After gaining initial access, the attackers attempted to establish persistence by registering their own phone numbers, authenticator apps, passkeys or software-based one-time password methods.
Compromised accounts were then used for Microsoft Graph API discovery, mailbox collection and high-volume downloads from SharePoint Online and OneDrive for Business.
Microsoft linked parts of the activity to Storm-3121 and Storm-3032. Infrastructure and tactics also overlapped with cybercrime and extortion clusters associated with ShinyHunters, UNC6671 and Helix, although the exact relationship between these groups remains unclear.

Recommended Actions After a Suspected Account Compromise:
Revoke active sessions and refresh tokens for affected users and temporarily disable accounts when necessary.
Review all authentication methods registered to the account, including phone numbers, authenticator apps, passkeys and TOTP methods. Remove any method that cannot be verified.
Reset passwords after sessions have been revoked and require phishing-resistant MFA for critical accounts.
Review Microsoft Entra ID sign-in and audit logs for unmanaged devices, new MFA registrations, device-code sign-ins, unusual locations and unexpected application access.
Investigate Microsoft Graph, SharePoint Online and OneDrive logs for high-volume enumeration, search and download activity.
Check Exchange Online for suspicious inbox rules, forwarding settings, delegations and REST/API-based mailbox access.
Search for and block related domains, URLs and IP addresses across email security, web filtering, DNS security, EDR and SIEM platforms.
If fraudulent payments may have been sent, contact the bank immediately. Require an independent verification channel before approving new beneficiaries or changes to ACH/payment instructions.
Some of the measures that can be taken to protect against these types of attacks include:
RouterOS versions should be kept up to date.
Internet-facing SSH and management services should be disabled.
Management access should be restricted to VPN connections or trusted IP addresses.
Unauthorized users and suspicious accounts should be regularly reviewed.
SSH keys and administrator passwords should be periodically renewed.
Suspicious scripts and scheduled tasks should be regularly checked.
RouterOS logs should be forwarded to a centralized SIEM/Syslog system.
Suspicious access attempts and anomalous activities should be continuously monitored.
For more detailed information, please contact our experts at info@zerosecond.ae





















Comments