Cybercriminals Exploit Passkey Phishing to Compromise Microsoft Cloud Accounts

Microsoft reveals two phishing campaigns targeting cloud accounts through deceptive emails.

3 min readCybersecurity

Microsoft has recently reported on two distinct phishing campaigns where cybercriminals are leveraging third-party email services to disseminate fraudulent messages aimed at financial gain. The first operation, which took place from August 3 to 5, 2026, saw the distribution of over a million scam emails. These messages were cleverly disguised as communications from chief executive officers, tricking recipients into believing they were legitimate. The attackers employed social engineering tactics centered around passkeys to infiltrate cloud environments, leading to potential data breaches. This alarming trend highlights the increasing sophistication of phishing schemes and the need for enhanced security measures to protect sensitive information in cloud services. Organizations are urged to remain vigilant and educate their employees about recognizing such scams to mitigate risks associated with these types of cyber threats.

Cybersecurity