Microsoft Warns of Passkey-Themed Phishing Attacks Targeting Corporate 365 Accounts

Threat actors linked to ShinyHunters and Helix use help desk impersonation and adversary-in-the-middle techniques to steal data

edit
By LineZotpaper
Published
Read Time2 min
Microsoft has revealed that threat actors linked to extortion gangs ShinyHunters and Helix are using passkey and single sign-on themed social engineering attacks to compromise corporate Microsoft accounts, stealing sensitive data from Microsoft 365 services since at least May 2026.

The campaign targets employees via phone calls or messages from individuals impersonating corporate IT help desks, Microsoft said in newly published research. Victims are told they must urgently update a passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to avoid losing access to corporate systems.

Attackers direct employees to phishing sites designed to resemble legitimate Microsoft login pages, with links sometimes sent via SMS to personal phones. While the lures revolve around passkeys, Microsoft noted that the attackers are not attempting to actually enroll a passkey. Instead, victims are tricked into signing in to adversary-in-the-middle (AiTM) phishing sites or using device-code authentication flows, allowing threat actors to capture credentials and session tokens.

Microsoft attributed the activity to multiple threat actors operating in the same extortion ecosystem, including groups tracked as Storm-3121 and Storm-3032. Storm-3121 is associated with ShinyHunters and Falcon extortion, while Storm-3032 is tied to members of the BlackFile extortion group that now operates under the Helix name.

Google Threat Intelligence has previously documented similar activity under the UNC6671 threat cluster, linking it to the same extortion gangs including BlackFile, Helix, Falcon, Pink, and Redact.

According to Microsoft, threat actors invest heavily in pre-attack research, gathering information from public sources such as social networking and professional profiling platforms. They register phishing domains that combine company names with words related to passkeys, SSO, key synchronization, and identity verification. Examples observed include passkeyhelpdesk[.]com, secure-passkey[.]com, and setupmypasskey[.]com. Attackers often place the victim company's name in a subdomain to make the portal appear more convincing.

Once inside a compromised account, Microsoft researchers documented the attackers mapping the environment, enumerating SharePoint sites, identifying privileged accounts, and accessing Azure infrastructure. The research detailed how attackers searched for sensitive data, including financial documents, intellectual property, and credentials stored in documents and configuration files. In some cases, threat actors attempted to set up email forwarding rules and establish persistence by creating new service principals with high privileges.

§

Analysis

Why This Matters

  • These attacks bypass traditional security measures by exploiting trust in help desk interactions and using legitimate authentication flows, making them difficult to detect.
  • The targeting of Microsoft 365 services means organisations across all sectors face potential data theft of intellectual property, financial records, and credentials.
  • The involvement of well-known extortion groups suggests stolen data may be used for double extortion ransomware tactics.

Background

Passkey authentication was widely adopted as a phishing-resistant alternative to passwords, but attackers are now weaponising the concept to lower victim suspicion. Adversary-in-the-middle (AiTM) phishing kits have become common among criminal groups, allowing real-time credential and session token theft. Device-code phishing exploits the legitimate device-code flow in Microsoft's authentication system, tricking users into approving access from an attacker-controlled client. The groups involved — ShinyHunters, Helix, BlackFile — have been linked to numerous high-profile data breaches and extortion campaigns.

Key Perspectives

Microsoft Security: Emphasises the extensive pre-attack research and sophisticated infrastructure used, urging organisations to enforce phishing-resistant MFA like FIDO2 security keys and to educate employees about help desk impersonation. Google Threat Intelligence: Independently tracked similar activity under UNC6671, confirming the overlap with extortion groups and the use of phone-based social engineering combined with passkey-themed phishing domains. Security researchers and CISOs: While the attack method is not technically novel, the high level of targeting and abuse of new authentication terms represents an evolving threat that requires ongoing user awareness training and conditional access policies.

What to Watch

  • Whether Microsoft implements additional protections in device-code authentication flows to detect anomalous use.
  • Further disclosures by Google or Microsoft linking these campaigns to specific data breaches or ransom demands.
  • Evolution of lures as organisations adopt passkey and SSO technologies, potentially increasing the attack surface.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.