# Microsoft details passkey-themed cloud-account phishing campaigns

_Sunday, September 13, 2026 at 6:11 AM EDT · Security · Latest · Tier 2 — Notable_

![Microsoft details passkey-themed cloud-account phishing campaigns — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZ2E2hmYwxfZ25xw5iPhCHaSDENcuEyEIaha9e_rIJCf68srth31FtjIiIlnOcEiSQDDuk2Vg-dQdNLfR753ePSoDntP3BS-MGbEH2DS8Ch5ihzhpiDZZm5UIzKCbL1vNJSwSABCYst8oG6Oa-7iBWaSF6WSTEkCJBAi9YEEwAmVEdGYvu-JWZnxwEX9ni/s1700-nu-rw-lo-l85-e365/ms-outlook.jpg)

Microsoft disclosed two campaigns that used third-party email delivery infrastructure and passkey-themed social engineering against enterprise accounts. In the cloud intrusions, attackers contacted employees by phone or message, directed them to counterfeit sign-in sites, then used adversary-in-the-middle or device-code authentication flows.

Microsoft said compromised accounts were used for Microsoft Graph activity, mailbox collection, and SharePoint and OneDrive downloads; attackers also added authentication methods in some cases to retain access. The activity has been detected since May 2026 and affected multiple accounts.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html)

---
Canonical: https://techandbusiness.org/newswire/N6Mar_B9EjOsRSBl1xWKO7
Retrieved: 2026-09-13T13:07:07.273Z
Publisher: Tech & Business (techandbusiness.org)
