← Blog · · df00tech

Microsoft Details Passkey Phishing Campaign Targeting Cloud Account Takeover

security-news campaign

Microsoft has disclosed two separate campaigns abusing trust in legitimate infrastructure to compromise victims. One involved sending over one million financial fraud scam emails between August 3-5, 2026, by impersonating CEOs and using third-party email delivery infrastructure. The other used passkey-themed social engineering to target Microsoft cloud environments.

Why It Matters

These campaigns show attackers adapting social engineering to newer authentication paradigms and to email infrastructure that recipients and filters tend to trust. Passkeys are widely promoted as a phishing-resistant improvement over passwords, so social engineering that targets the passkey enrollment or recovery workflow rather than the credential itself represents a meaningful shift for defenders who may have assumed passkey adoption alone reduces account takeover risk. The scale of the CEO-fraud email blast (over a million messages in a 48-hour window) also indicates continued high-volume abuse of third-party mail delivery services to evade reputation-based filtering.

What Defenders Should Watch For

  • Review sign-in and authentication method change logs for Microsoft 365/Entra ID accounts, particularly events tied to passkey or FIDO2 credential registration, especially outside expected devices or locations.
  • Scrutinize inbound mail flagged as originating from legitimate-looking but third-party bulk email or delivery services, particularly messages impersonating executives requesting financial action.
  • Educate users and help-desk staff on social engineering tactics specifically targeting passkey setup and account recovery flows, not just traditional password phishing.
  • Review conditional access and MFA/passkey enrollment policies to ensure new credential registration requires strong verification of the requesting user's identity.

This is based on early reporting from Microsoft, and the technical details of the passkey phishing technique were not fully specified in the source material at the time of writing. This is developing intelligence with no CVE association; for the full report see The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.