# Microsoft links passkey-themed phishing to ShinyHunters and Helix extortion crews

_Friday, September 11, 2026 at 1:26 PM EDT · Security, Products · Latest · Tier 2 — Notable_

![Microsoft links passkey-themed phishing to ShinyHunters and Helix extortion crews — Primary](https://www.bleepstatic.com/content/hl-images/2025/08/04/Microsoft-365.jpg)

Microsoft says threat actors tied to the ShinyHunters, Helix and other extortion gangs have used passkey- and single sign-on-themed social engineering since May 2026 to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.

Attackers research targets, then call or message employees while impersonating IT help desks and urge urgent passkey, MFA or SSO updates. Microsoft says the lures do not enroll a passkey; they push victims to adversary-in-the-middle phishing sites or device-code authentication flows that capture credentials and session tokens.

Microsoft attributes the activity to groups it tracks as Storm-3121 and Storm-3032, overlapping with Google's UNC6671 cluster.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/)

---
Canonical: https://techandbusiness.org/newswire/jdkSs729r2l77cwgkdRDUB
Retrieved: 2026-09-12T02:50:18.699Z
Publisher: Tech & Business (techandbusiness.org)
