Microsoft Cloud accounts stolen in highly complex impersonation and passkey phishing campaign
Passkeys have all but eliminated password theft, so what now? Criminals have a solution.
Microsoft has issued an alert regarding a complex cyber attack targeting cloud accounts. The attack involves a sophisticated impersonation and passkey phishing scheme. Victims are called by what appears to be their organization's IT help desk, instructed to update their passkey or MFA immediately to prevent operational disruptions.
After the phone call, victims receive an SMS with a link leading to a fake Microsoft login page, a result of adversary-in-the-middle techniques. This site is used to either grant the attacker access or steal credentials. The attackers invest significantly in research, using public information from social networking and professional platforms to gather data about employees and organizational structures.
In some instances, compromised accounts are exploited to spread similar passkey-themed messages through Microsoft Teams. The campaign has been ongoing since at least May of this year, targeting the exfiltration of files from SharePoint, OneDrive, and email data from Microsoft Exchange Online.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.