# Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft revealed two distinct attack campaigns exploiting third-party email infrastructure and passkey-based social engineering to compromise cloud environments and steal data.

The first campaign spanned August 3-5, 2026, and involved attackers sending over one million fraudulent emails. Threat actors masqueraded as chief executive officers to deliver financial fraud scam messages through compromised third-party email delivery systems. This approach bypasses traditional email security controls by routing malicious content through legitimate infrastructure, increasing delivery success rates and evading reputation-based filtering.

The second campaign shifted tactics entirely. Attackers leveraged passkey-themed social engineering to target Microsoft cloud account holders. Passkeys, which replace passwords with cryptographic authentication tied to physical devices, represent Microsoft's push toward passwordless security. Threat actors capitalized on user unfamiliarity with this newer authentication method by crafting convincing phishing scenarios centered on passkey registration or recovery processes. When users interacted with malicious prompts, attackers gained credential access to cloud environments.

The passkey attack vector proves particularly effective because adoption remains uneven across organizations. Many users remain unfamiliar with legitimate passkey workflows, making them vulnerable to social engineering that mimics official Microsoft communications. Attackers leveraged this knowledge gap to convince victims to surrender authentication credentials or approve unauthorized account access.

Once inside cloud accounts, attackers exfiltrated sensitive data. Microsoft did not specify the exact volume of compromised accounts or data volume stolen, but the campaign's scale suggests significant organizational impact. Cloud breaches of this nature expose customer data, intellectual property, financial records, and internal communications.

The use of third-party email infrastructure reflects a broader trend where attackers compromise legitimate services rather than operating their own mail servers. This approach reduces infrastructure costs and dramatically improves deliverability. Microsoft and other cloud providers maintain IP reputation systems that flag suspicious mail servers, but legitimate infrastructure carries trusted status. By hijacking these systems, attackers piggyback on established reputation signals.

The campaigns underscore the dual threat landscape facing cloud adopters. Organizations cannot rely solely on authentication mechanisms like passkeys. Social engineering remains devastatingly effective against human operators who make the final decision to click, approve, or divulge credentials.

Microsoft recommends several defensive steps. Organizations should implement security awareness training focused on passkey authentication flows, teaching employees to recognize legitimate versus fraudulent requests. Security operations teams should monitor for unusual account access patterns, particularly from unexpected geographies or devices. Multi-factor authentication beyond passkeys, such as hardware security keys or phone-based verification, provides defense-in-depth.

Email security must filter based on content analysis and sender verification rather than reputation alone. Organizations should enforce DMARC, SPF, and DKIM protocols on all outbound domains to prevent spoofing. Cloud account logging and threat detection tools should flag suspicious sign-ins, especially those followed by mass data access or export events.

The campaigns reflect attackers' shift toward targeting cloud infrastructure rather than on-premises networks. As organizations migrate workloads to Azure and Microsoft 365, cloud accounts become high-value targets. A single compromised cloud admin account grants access to terabytes of data and enables lateral movement across tenant resources.