← Back to feed
PhishingEmerging1 sourceSep 9, 2026 · 17:41via Microsoft Security Blog

Passkey-themed social engineering leads to identity and cloud compromise

Brief

In this article

  • Attack chain overview
  • Attribution
  • Mitigation and protection guidance
  • Learn more

Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs.

Microsoft Security Research assesses that this sequence is consistent with automated collection from compromised cloud identities using proxy-associated infrastructure, the activity has been observed since May 2026.

The activity begins with identity-focused social engineering and impersonation infrastructure, proceeds through authentication persistence and cloud reconnaissance, and is followed by targeted data access and activity consistent with data collection and potential exfiltration.

Read more on Microsoft Security Blog→