HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Passkey‑Themed Phishing Attacks Harvest Microsoft 365 Credentials and Data

Threat actors have used passkey‑styled phishing to steal Microsoft 365 credentials, leading to confirmed data exposure across multiple enterprises. The incident highlights the need for hardened authentication controls and continuous audit evidence for access‑control assurance.

Verisq™ Intelligence · 📅 September 11, 2026 · 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Passkey‑Themed Phishing Attacks Harvest Microsoft 365 Credentials and Data

What Happened – Since May 2026, threat actors linked to the ShinyHunters, Helix and related extortion groups have run phishing campaigns that masquerade as “passkey”, MFA or SSO updates. Victims are lured to attacker‑in‑the‑middle login pages or device‑code flows that capture Microsoft 365 credentials and session tokens, enabling data theft from corporate mail, SharePoint and Teams.

Why It Matters for Trust & Control Assurance

  • The scenario tests the effectiveness of identity‑centric controls (credential protection, MFA enforcement, and verification of authentication flows).
  • Continuous control‑assurance programs need verifiable evidence that MFA and passkey processes are hardened, monitored and cannot be subverted by social engineering.
  • Demonstrating robust authentication governance provides audit‑ready proof that access‑control objectives are being met.

Who Is Affected – Enterprises of all sizes that rely on Microsoft 365 for email, collaboration and file storage; particularly sectors with high‑value intellectual property or regulated data (finance, health, legal, technology).

Recommended Actions

  • Review and tighten MFA policies: enforce phishing‑resistant methods (e.g., FIDO2 security keys) and disable legacy authentication.
  • Deploy anti‑phishing controls that inspect URLs, block suspicious domains, and flag device‑code flow requests.
  • Capture and retain logs of authentication events (sign‑ins, token issuance) for continuous monitoring and audit evidence.

Technical Notes – Attack vector: targeted phishing (email, SMS, voice) using AiTM sites that mimic Microsoft login pages; exploitation of device‑code authentication flow to obtain OAuth tokens. No new CVE; the weakness is procedural/social‑engineering. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →