Skip to main content
CyberSingle-sourceMediumDeveloping
5.1

Passkey-themed phishing targets Microsoft 365, linked to extortion gangs

Microsoft reports threat actors tied to ShinyHunters, Helix, and other extortion groups are using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts and exfiltrate data from Microsoft 365. The attack exploits user trust in passkey adoption, a novel vector. This signals an escalation in credential-based attacks against cloud services, with potential for widespread data breaches.

BleepingComputer1 day agoUSengCredibility 39%View source

Score Breakdown

Mosaic Score5.1
Confidence0.7
Significance0.5
Source credibility0.4
Source

Related signals

8 found