<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Passkey-themed phishing attacks lead to Microsoft 365 data theft]]></title><description><![CDATA[<p dir="auto">Microsoft is warning that threat actors tied to extortion groups including <strong>ShinyHunters</strong> and <strong>Helix</strong> are running social engineering campaigns built around <strong>passkey</strong> and <strong>single sign-on</strong> themes to break into corporate <strong>Microsoft</strong> accounts and exfiltrate data from <strong>Microsoft 365</strong> services.</p>
<p dir="auto">The attacks rely on convincing users to hand over access under the guise of passkey enrollment or SSO-related activity, rather than exploiting a software flaw. That means the entry point is the user, and the payoff for the attackers is access to cloud-hosted corporate data.</p>
<p dir="auto">Key points to keep in mind:</p>
<ul>
<li>The campaigns are attributed to multiple extortion gangs, among them <strong>ShinyHunters</strong> and <strong>Helix</strong>.</li>
<li>Targets are corporate <strong>Microsoft</strong> accounts, with data theft focused on <strong>Microsoft 365</strong> services.</li>
<li>The lures center on <strong>passkey</strong> and <strong>single sign-on</strong> themes, which makes them harder to spot since both are legitimate, everyday authentication topics.</li>
<li>There is no indication in the reporting of a specific CVE or product vulnerability being exploited here; this is a social engineering problem, not a patchable bug.</li>
</ul>
<p dir="auto">Because these attacks abuse trust in authentication features rather than technical weaknesses, the usual defenses matter more than ever: strong user awareness around credential and passkey requests, conditional access and phishing-resistant authentication policies, and monitoring for unusual sign-ins or data access in <strong>Microsoft 365</strong>. Organizations should also review how passkey rollouts are communicated internally, since attackers are mimicking exactly that kind of messaging.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft" target="_blank" rel="noopener noreferrer nofollow ugc">BleepingComputer</a></p>
<p dir="auto">Has your organization seen any passkey or SSO-themed phishing attempts lately, and how are you handling them?</p>
]]></description><link>https://xploitlk.com/topic/300/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 05:34:16 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/300.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 11 Sep 2026 18:30:21 GMT</pubDate><ttl>60</ttl></channel></rss>