Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
- ID
- 23927
- Status
- summarized
- Published
- 13 Sep 2026, 6:11 PM
- Fetched
- 13 Sep 2026, 7:15 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 13 Sep 2026, 7:17 PM
- Tags
- Audience
- developerssaas_founders
What happened
Microsoft disclosed two campaigns where attackers sent over 1 million scam emails between August 3-5, 2026, impersonating CEOs to trick accounts payable departments into ACH transfers for a fake ServiceNow subscription, using generative AI to craft tailored email templates and forged email threads. A separate campaign used passkey-themed social engineering to breach Microsoft cloud environments and exfiltrate data. Registered impersonation domains included service-nowinc[.]com and domainlify[.]net.
Why it matters
If you ship passkey-based authentication, this confirms attackers are actively building phishing lures around passkey enrollment flows for Microsoft cloud accounts. Review your passkey registration and recovery paths for social engineering exposure, and brief finance teams that AI-generated executive impersonation emails now include fabricated invoice threads and matching signatures.
Discussion angle
Passkeys are marketed as phishing-resistant, but this campaign shows attackers are shifting to social-engineer the enrollment and recovery steps instead—what does that mean for how you design onboarding flows?