Are your establishment’s Microsoft cloud accounts as secure as they seem? A recent phishing operation shows how threat actors can exploit authentication workflows to access sensitive business data.
Why More Businesses Are Moving to the Cloud
Cloud technology now sits at the center of many everyday business operations. Companies use platforms such as Microsoft 365 to keep essential tools and information within one connected digital environment.
When adopted correctly, cloud-based tools can bring the following worthwhile benefits:
- Flexible access to essential workplace resources
- Centralized storage for important business files
- Easier collaboration between employees and departments
- Scalable resources that adapt to changing needs
Unfortunately, the growing value and popularity of these platforms also make them appealing to cybercriminals. Microsoft Security Research has tracked a sophisticated campaign since May 2026 that targets employees through familiar authentication procedures.
How Does the Campaign Unfold?
This passkey-themed phishing campaign goes beyond sending a convincing email and hoping someone clicks. Threat actors combine direct contact with carefully crafted authentication prompts to make their requests appear legitimate.
These social engineering attacks can ultimately result in identity and cloud compromise. The scheme develops through several stages, with each one bringing the intruder closer to valuable company resources.
Research the Target
Attackers may study publicly available information about employees and company structures beforehand. These impersonation techniques can make an unexpected IT request seem more credible.
Create a Convincing Pretext
Next comes direct contact. The caller presents the authentication change as urgent, often while posing as IT support. Victims may then receive a text directing them to a website that resembles a legitimate Microsoft sign-in experience.
Hijack the Authentication Flow
The passkey itself is not necessarily the target. One approach uses adversary-in-the-middle phishing to capture credentials and session tokens. Alternatively, a victim may enter a supplied device code on Microsoft’s legitimate authentication page and unknowingly authorize an attacker-controlled client.
Establish Persistent Access
Successful entry can enable further activity. An intruder may register another authentication method under their control. Microsoft has also observed reconnaissance through Microsoft Graph before attackers access SharePoint, OneDrive, or Exchange content available to the compromised user.
This progression can turn credential theft into a much broader threat to Microsoft cloud accounts.
Put Stronger Barriers Around Your Cloud
Businesses can reduce their exposure through a combination of technical safeguards and employee awareness. Microsoft recommends the following strategies:
- Use phishing-resistant MFA: FIDO2 passkeys or Windows Hello for Business can provide stronger protection through Conditional Access.
- Verify IT requests: Employees need a trusted channel to confirm unexpected authentication instructions before responding.
- Control unmanaged devices: Conditional Access policies can prevent untrusted hardware from reaching sensitive cloud resources.
- Review authentication changes: Treat unfamiliar devices or newly registered methods as potential warning signs, especially after unusual sign-ins.
- Watch cloud activity: Abnormal Microsoft Graph behavior, large file downloads, or suspicious mailbox access deserve closer investigation.
Attackers increasingly combine technical deception with convincing human interaction. Strong proactive measures around your company’s Microsoft cloud accounts can make these elaborate schemes much harder to pull off.
