Microsoft has disclosed details of two separate attack campaigns — one that blasted more than a million fraudulent emails impersonating company executives over just three days, and another using passkey-themed deception to compromise cloud accounts. The tech giant's Security Research team documented the operations in a new report, showing how attackers are combining AI-generated content, executive impersonation, and social engineering to breach corporate systems. Both campaigns targeted U.S. enterprises across industries including IT services, consumer goods, real estate, and manufacturing.
The first campaign ran between August 3 and 5, 2026, sending fraudulent messages that appeared to come from CEOs at victim companies. The emails urged accounts payable staff to authorize Automated Clearing House transfers for a supposed ServiceNow annual subscription. Attackers registered impersonation domains like service-nowinc[.]com and domainlify[.]net to add legitimacy. The scheme layered multiple deception tactics: fake invoices, fabricated email threads showing prior approval conversations, and signatures that included the real names and email addresses of CEOs, CFOs, and presidents at targeted organizations. Evidence suggests the operators used generative AI to create email templates and personalize messages for recipients.
The second campaign, detected since May 2026, revolves around cloud intrusions following suspicious sign-ins where threat actors add their own authentication methods to compromised accounts. According to Microsoft, the attack typically begins with a phone call or text message to an employee's personal device, with the attacker posing as IT help desk staff and claiming the worker must immediately update their passkey, multi-factor authentication, or single sign-on setup to prevent access disruptions. Victims receive SMS links to counterfeit websites mimicking Microsoft's legitimate sign-in page. The report finds these sites guide users through adversary-in-the-middle or device-code authentication flows that either capture credentials or trick employees into granting access on the attacker's behalf. Once inside, threat actors register their own phone number or authenticator app as a second factor, establishing persistent access without needing the victim's continued participation. Microsoft observed attackers conducting extensive reconnaissance using the Graph API, enumerating users and permissions, inspecting mailboxes, and downloading large volumes of data from SharePoint Online and OneDrive — activity that stretched from several hours to multiple days.
Microsoft attributes the cloud intrusion activity to threat actors including Storm-3121 and Storm-3032, with the latter designation referring to a set of actors that splintered from the BlackFile group and now operate under the Helix extortion brand. The report notes these operations overlap with a loose-knit cybercrime collective tracked as Cordial Spider, O-UNC-045, PREY-0058, and UNC6671 across the security community. Attackers registered domains built around passkey and SSO themes — including passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, and integratedsso[.]com — often incorporating the target company's name as a subdomain to appear authentic. The research highlights a critical detection challenge: Microsoft Graph abuse rarely looks suspicious when viewed through individual API calls, requiring instead a holistic assessment of behavioral progression and cross-event correlation. Organizations face a persistent threat from adversaries who invest heavily in pre-attack research, gathering employee information from social networking and professional platforms, then using that intelligence to craft convincing lures that bypass traditional security awareness. The convergence of AI-assisted social engineering and sophisticated post-compromise techniques means attackers can now move from initial access to sustained data theft with minimal friction, turning temporary breaches into extended exfiltration operations that traditional defenses struggle to detect.

