Observed attack sequence | Image: Microsoft
At a glance
Microsoft threat analysts reported active cloud intrusions utilizing passkey social engineering to breach enterprise tenants on September 9, 2026. These targeted campaigns combine voice phishing with automated cloud data theft. Attackers trick corporate employees into surrendering session tokens and authentication approvals.
| Field | Details |
|---|---|
| Actor or Group | Storm-3121, Storm-3032 (Helix), and associated extortion syndicates |
| Activity Type | Voice phishing (vishing), AiTM phishing, device code abuse, and data theft |
| Targets or Victims | Corporate employees, executives, and IT staff across enterprise cloud tenants |
| Scale | Multiple corporate accounts compromised across SharePoint, OneDrive, and Exchange |
| Jurisdiction Status | Tracked by private threat researchers; no criminal indictments announced yet |
| Source | Microsoft Security Research and Arctic Wolf |
Executive Summary
Attackers phone corporate workers while posing as internal IT helpdesk technicians. The callers use urgent passkey registration requests to bypass multifactor authentication defenses. Once inside, the operators enroll unauthorized authentication devices and extract sensitive company files.
What Happened in the Cloud Intrusions
The intrusion sequence begins with an unexpected phone call or text message sent to an employee. An attacker poses as a corporate technical support representative. The caller creates false urgency by claiming security credentials require an immediate update. Furthermore, the caller warns that access will end without prompt action.
Next, the intruder directs the victim to a fake authentication website. This site mimics the organization’s standard corporate login portal. As Microsoft researchers observed, “Despite the frequent use of passkey-themed lures, passkey enrollment is often not the actor’s true objective.” Instead, the intruders use this cover story to guide victims into adversary-in-the-middle portals or device-code authorization sequences.
In device-code attacks, the employee enters a supplied code on the official Microsoft authentication page. This action grants account authorization directly to an attacker-controlled client. Meanwhile, adversary-in-the-middle sites intercept active session tokens and user passwords. Because workers often open these links on personal mobile phones, corporate endpoint sensors fail to record the initial contact.
Establishing Authentication Persistence
After securing initial access, the attackers register secondary authentication factors under their control. They add unauthorized mobile phone numbers or virtual authenticator applications. According to Microsoft, “By registering an actor-controlled MFA method, the threat actor ensured that future authentication challenges could be satisfied using a factor they controlled.” Consequently, the intruders maintain access even after the victim changes their password.
Reconnaissance Through Microsoft Graph
Once persistence is established, the intruders inventory the corporate tenant. The operators query Microsoft Graph endpoints to catalog user accounts, groups, and assigned administrative permissions. They inspect document libraries across SharePoint Online and OneDrive for Business. In addition, the intruders examine email folders and review message attachments through cloud application programming interfaces.
Technical documentation in the Microsoft security research report details how the attackers pace their requests. The actors systematically query tenant resources while rotating source internet protocol addresses. This rotation helps the attackers evade automated detection rules.
Who Is Behind the Activity
Microsoft Threat Intelligence links these intrusions to several financially motivated actors with moderate-to-high confidence. The primary tracked clusters include Storm-3121 and Storm-3032. Security teams track Storm-3121 as an access broker that sells stolen credentials to extortion groups like ShinyHunters and Falcon.
Meanwhile, Storm-3032 represents a group that splintered from the BlackFile cybercrime gang. This splinter faction now conducts attacks under the Helix extortion banner. Independent research from Arctic Wolf corroborates these findings, tracking similar activity under cluster PREY-0058 and UNC6671. These groups share proxy infrastructure and deceptive registration habits.
The actors frequently register disposable domains through the Nicenic registrar. They embed victim company names into subdomains, such as companyname.secure-passkey.com or companyname.integratedsso.com. Furthermore, the operators deploy custom Node.js automation to speed up account exploitation.
Impact and Operational Scale
These intrusions have impacted numerous organizations across multiple commercial sectors. Once inside, the threat actors extract valuable corporate data and internal communications. Attackers execute automated scripts using tools like python-httpx to collect files from SharePoint and OneDrive.
However, the actors avoid abrupt bulk downloads that could trigger threshold alarms. Instead, the intruders maintain a steady, disciplined pace. Microsoft observed that the attackers generally access fewer than 1,000 files or emails within any one-hour window. This controlled rate allows exfiltration to continue for several days without raising alarms.
The attackers also harvest corporate mailboxes using the One Outlook Web application interface. The resulting loss of proprietary data exposes victim companies to extortion demands. Extortion groups threaten to publish sensitive files unless the victim pays a ransom within 72 hours.
What Comes Next and Defense Guidance
Defenders must update their security controls to stop passkey social engineering attacks. Traditional password resets do not protect an account if an attacker added a secondary factor. Therefore, security administrators must investigate identity settings whenever anomalous sign-ins occur.
Recommended Defensive Steps
Organizations should adopt several essential defenses to protect their cloud infrastructure:
- Enforce phishing-resistant multifactor authentication, such as FIDO2 hardware keys, across all accounts.
- Restrict device code flow permissions in Microsoft Entra ID to block unauthorized token issuance.
- Audit user profiles for newly registered authenticator apps, especially entries labeled with generic device names.
- Monitor Microsoft Graph audit logs for unusual spikes in directory enumeration and document discovery queries.
- Train personnel to verify helpdesk communications through official corporate channels before opening texted links.
By enforcing hardware-backed credentials and monitoring identity telemetry, security teams can halt these intrusion chains before data exfiltration begins.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!