Back to News
Cybersecurity

Emerging Threat: Passkey Phishing Targets Microsoft Cloud Accounts

Microsoft reveals new phishing campaigns exploiting passkeys to compromise cloud accounts and steal sensitive data.

Microsoft has recently unveiled details of two distinct phishing campaigns that leverage third-party email infrastructure to distribute financial fraud messages and utilize passkey-themed social engineering tactics. The first campaign, which occurred between August 3 and 5, 2026, involved the distribution of over a million scam emails impersonating high-level executives, effectively deceiving recipients and leading to unauthorized access to Microsoft cloud environments.

These developments highlight a growing threat landscape for businesses that rely on cloud services. Organizations must enhance their cybersecurity protocols to combat sophisticated phishing attempts and protect their sensitive data. Implementing multi-factor authentication (MFA), employee training on recognizing phishing attempts, and closely monitoring account access are practical steps that can mitigate risks. This situation underscores the importance of robust cybersecurity measures, particularly in an era where attackers are increasingly using advanced social engineering techniques to exploit weaknesses in human behavior and technology alike.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html)*