Microsoft Security Intelligence Uncovers Sophisticated Two-Pronged Cyberattack Campaign Involving Generative AI and Passkey-Themed Social Engineering

Microsoft’s security research division has issued an urgent warning to enterprise organizations following the discovery of two distinct, highly sophisticated cyberattack campaigns that have emerged throughout the latter half of 2026. The identified threats demonstrate a concerning evolution in criminal methodology, shifting from broad, automated spam toward highly personalized, multi-layered social engineering. These campaigns—one focusing on AI-assisted financial fraud and the other on cloud environment infiltration via passkey-themed lures—represent a significant escalation in the tactics used by threat actors to bypass modern security controls, including multi-factor authentication (MFA).
The first of these operations, which gained momentum in early August 2026, involves the use of generative artificial intelligence to craft convincing executive impersonation emails. These messages are designed to deceive accounts payable departments into authorizing fraudulent Automated Clearing House (ACH) transfers. The second campaign, which has been under observation since May 2026, utilizes social engineering to target the identity infrastructure of organizations, specifically leveraging "passkey" updates as a pretext to compromise cloud-based accounts and gain unauthorized access to sensitive corporate data stored in SharePoint and OneDrive.
The Anatomy of an AI-Driven Financial Fraud Campaign
Between August 3 and August 5, 2026, Microsoft detected a massive wave of more than one million scam emails targeting enterprise users across the United States. The sectors most heavily affected include discrete manufacturing, consumer goods, real estate, and professional IT services.

Unlike traditional "spray-and-pray" phishing attacks, this campaign utilized generative AI to create contextually relevant email templates. By mimicking the tone, signature, and communication style of high-ranking executives—specifically CEOs and CFOs—the attackers significantly reduced the level of skepticism among finance personnel. The campaign followed a rigorous execution cycle:
- Preparation: Actors registered custom domains specifically designed to impersonate the target company’s brand and internal executive hierarchy.
- Fabrication: Using AI, the attackers generated professional-looking invoices for a non-existent "ServiceNow annual subscription."
- Narrative Construction: Rather than sending a single email, the attackers embedded forged email threads within the message to make it appear as though the invoice had already been vetted and approved by internal leadership.
- Execution: Finance employees were pressured via these seemingly legitimate internal threads to initiate immediate ACH transfers to attacker-controlled accounts.
This approach represents a shift toward "narrative-driven" social engineering. By weaving a story—complete with supporting documentation and internal "approvals"—the threat actors exploited the human element of security protocols, effectively bypassing standard technical filters that might otherwise flag isolated suspicious links or attachments.
Passkey-Themed Social Engineering and Cloud Compromise
While the financial fraud campaign targeted the wallet, the second campaign identified by Microsoft targeted the identity. Since May 2026, a loose-knit but highly coordinated group of cybercriminals has been conducting a series of cloud-based intrusions. This activity, which Microsoft links to actors designated as Storm-3121 and Storm-3032, relies on "vishing" (voice phishing) and SMS-based social engineering.
The attack typically initiates with a phone call or text message to an employee’s personal device. The caller, posing as an internal IT help desk representative, conveys a sense of urgency, claiming that the employee must update their passkey, MFA settings, or Single Sign-On (SSO) configuration to prevent a lockout.

Once the victim is hooked, they are directed to a counterfeit portal that perfectly replicates the Microsoft sign-in experience. By utilizing adversary-in-the-middle (AitM) techniques or exploiting device-code authentication flows, the attackers capture the user’s credentials and session tokens. In some instances, the actors have successfully used compromised accounts to move laterally through an organization, leveraging Microsoft Teams to send similar malicious lures to other employees, thereby accelerating the spread of the breach.
Chronology and Attribution: Tracking the E-Crime Collectives
The cybersecurity community has been tracking the infrastructure associated with these campaigns under several monikers, including UNC6671, Cordial Spider, and PREY-0058. These groups are believed to be part of a larger ecosystem of cybercriminals who share initial access playbooks and commoditized phishing panels.
The involvement of Storm-3032, which Microsoft identifies as the group behind the "Helix" extortion brand, suggests that the primary goal of these attacks is to secure a long-term, persistent foothold in victim environments. By registering domains that include the target company’s name as a subdomain—such as "companyname.malicious-service.com"—the actors exploit the natural trust employees place in their own organizational branding.
Following the initial breach, the objective of these actors is to transform temporary access into permanent control. Microsoft researchers observed that once the attackers gain access to an account, they immediately enroll their own MFA methods—such as a specific phone number, an authenticator app, or a software-based OTP token. This provides the attackers with a "backdoor" that remains valid even if the original user changes their password or if the organization revokes active sessions.

Technical Implications: The Challenge of Graph API Abuse
One of the most alarming aspects of these intrusions is the tactical use of the Microsoft Graph API. After establishing persistence, attackers use the API to enumerate sensitive files, download data from SharePoint and OneDrive, and monitor email traffic.
Microsoft emphasizes that identifying this activity is difficult because individual API calls often appear benign. For example, a single file download or a query for mailbox information does not necessarily trigger an alert in most Security Information and Event Management (SIEM) systems. Detection, therefore, requires a holistic view of user behavior. Security teams must correlate seemingly disparate events—such as a successful MFA registration from an unusual location followed by an atypical volume of Graph API activity—to identify the intrusion in progress.
Broader Impact and Organizational Defense Strategies
The implications of these findings are profound. As organizations continue to move their operations to the cloud, the "identity" has become the new perimeter. When that identity is compromised via sophisticated social engineering, traditional network-level defenses become largely irrelevant.
To mitigate these threats, Microsoft recommends a multi-layered defense strategy:

- Holistic Behavioral Monitoring: Security operations centers (SOCs) should shift from alert-based monitoring to behavioral analytics. Focus on the sequence of events rather than individual actions, such as the registration of a new MFA device followed by unusual access to internal document repositories.
- Strengthening Help Desk Protocols: Organizations must implement stricter verification procedures for IT support requests. Employees should be trained to verify the identity of "IT support" personnel through an established, official internal channel before making any changes to their authentication settings.
- Phishing-Resistant MFA: Transitioning to FIDO2-compliant security keys or certificate-based authentication can significantly reduce the risk of AitM attacks. Unlike traditional SMS or OTP-based MFA, these methods are resistant to the credential harvesting techniques employed in the passkey-themed campaigns.
- Zero Trust Architecture: By assuming that a breach is always possible, organizations can limit the "blast radius" of a compromised account. Implementing strict conditional access policies that restrict API access based on device health, location, and user risk levels is essential.
The emergence of these campaigns signals that threat actors are becoming increasingly adept at leveraging the very tools meant to protect organizations—such as MFA and SSO—against them. The shift toward AI-generated lures and sophisticated, narrative-driven phishing indicates that the human element remains the most vulnerable vector in the corporate security landscape. As these groups continue to iterate on their tactics, the collaboration between security vendors and enterprise defenders will be paramount in curbing the impact of these persistent, well-funded adversaries. The battle for digital security has moved beyond simply blocking malicious code; it is now a fight against highly convincing, socially engineered deception.






