Passkey-themed social engineering leads to identity and cloud compromise

Published September 9, 2026

Attackers posing as IT support call or text people, trick them into signing into fake Microsoft pages, and steal their cloud accounts. They then snoop around, copy files, and send data out slowly to avoid being caught.

Report priority
Medium
Targets
Threat actor: Storm-3121, Storm-3032

How it works

  • Attackers call or text people pretending to be IT support.
  • They ask victims to sign into fake Microsoft pages using their real Microsoft account.
  • Once logged in, the attackers grab the victim's password and device codes.
  • They then add fake two-factor codes to the account so they can keep coming back.
  • After that, they use Microsoft's internal tools to find out who else has access to what files and emails.
  • Finally, they copy large amounts of data from SharePoint, OneDrive, and Outlook and send it out slowly to avoid getting noticed.

What to do

If you got a call or text from an unknown number asking you to sign into your Microsoft account, check if you see any unfamiliar two-factor codes or devices listed under your account security settings. If you see anything suspicious, change your password and review your recent sign-ins at Microsoft Security Dashboard.

If you think your account might be compromised, go to Microsoft's account security page and check for any unauthorized devices or codes. Change your password immediately and enable multi-factor authentication if it's not already. Also, watch for unusual activity in your emails and files, and report any suspicious behavior to Microsoft support.

Technical details

Affected software: Threat actor: Storm-3121, Storm-3032

In May 2026, Storm-3121 and Storm-3032 started calling people pretending to be Microsoft IT support. They told victims their accounts were locked and asked them to sign in on a fake Microsoft page. Once the victims entered their passwords, the attackers took over their accounts, added fake two-factor codes, and started copying files from SharePoint and Outlook.

A passkey-themed social engineering campaign targeting cloud accounts began in May 2026, exploiting Microsoft authentication flows to bypass multi-factor authentication (MFA). Attackers impersonate IT support via phone or SMS, tricking victims into visiting phishing sites mimicking Microsoft sign-in pages. By intercepting credentials through adversary-in-the-middle attacks or device code authentication, they add unauthorized MFA methods to maintain persistence.

Using the Microsoft Graph API, they map user permissions, groups, and resources before exfiltrating data from SharePoint, OneDrive, and Exchange at controlled rates to evade detection. The campaign is tracked under OTX-6aa1c27fd351a18fbe0a8219.