Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Threat Intelligence
  5. Passkey-themed phishing attacks lead to Microsoft 365 data theft

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Scheduled Pinned Locked Moved Threat Intelligence
microsoft
1 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Microsoft is warning that threat actors tied to extortion groups including ShinyHunters and Helix are running social engineering campaigns built around passkey and single sign-on themes to break into corporate Microsoft accounts and exfiltrate data from Microsoft 365 services.

    The attacks rely on convincing users to hand over access under the guise of passkey enrollment or SSO-related activity, rather than exploiting a software flaw. That means the entry point is the user, and the payoff for the attackers is access to cloud-hosted corporate data.

    Key points to keep in mind:

    • The campaigns are attributed to multiple extortion gangs, among them ShinyHunters and Helix.
    • Targets are corporate Microsoft accounts, with data theft focused on Microsoft 365 services.
    • The lures center on passkey and single sign-on themes, which makes them harder to spot since both are legitimate, everyday authentication topics.
    • There is no indication in the reporting of a specific CVE or product vulnerability being exploited here; this is a social engineering problem, not a patchable bug.

    Because these attacks abuse trust in authentication features rather than technical weaknesses, the usual defenses matter more than ever: strong user awareness around credential and passkey requests, conditional access and phishing-resistant authentication policies, and monitoring for unusual sign-ins or data access in Microsoft 365. Organizations should also review how passkey rollouts are communicated internally, since attackers are mimicking exactly that kind of messaging.

    Source: BleepingComputer

    Has your organization seen any passkey or SSO-themed phishing attempts lately, and how are you handling them?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World