Microsoft Warns of Passkey Lures and Invoice Scams Targeting Cloud Accounts

Microsoft has reported two separate phishing operations that use trusted services, executive impersonation and passkey-related lures to steal money or gain access to corporate cloud environments.One c...

Microsoft has reported two separate phishing operations that use trusted services, executive impersonation and passkey-related lures to steal money or gain access to corporate cloud environments.

One campaign sent more than one million fraudulent emails over a three-day period in August 2026, according to Microsoft. The messages impersonated senior leaders at targeted organizations and asked accounts-payable staff to make ACH payments for an alleged ServiceNow subscription renewal. Targets were primarily U.S. enterprises in industries including IT services, consumer products, real estate and manufacturing.

The operators used third-party email delivery infrastructure and registered lookalike domains to make the requests appear credible. Their messages reportedly combined fake invoices, forged approval chains, vendor branding and signatures using the names of real executives. Microsoft said the campaign appeared to use generative AI to help produce tailored email templates and recipient-specific drafts.

Passkey-themed calls and messages

A second set of incidents, observed since May 2026, involved social engineering designed to compromise Microsoft cloud identities. Attackers contacted employees through personal phone numbers, SMS messages and, in some cases, Microsoft Teams. Posing as IT support staff, they urged victims to update passkey, MFA or single sign-on settings to prevent an alleged account interruption.

Victims were directed to counterfeit sign-in pages or guided through adversary-in-the-middle and device-code authentication flows. Rather than always stealing passwords, the attackers could persuade users to approve access or enroll an authentication method controlled by the adversary.

After gaining access, the actors were seen adding new MFA options, conducting suspicious Microsoft Graph API activity, downloading data from SharePoint and OneDrive, and collecting mailbox information through REST APIs. In one case, an unusual sign-in from an unmanaged device was followed by attempts to enumerate internal services and sensitive files.

Defensive measures

  • Train finance teams to independently verify payment-change or invoice requests through known contact channels.
  • Require out-of-band validation for help-desk requests involving MFA, passkeys or device registration.
  • Monitor for newly enrolled authentication methods, unfamiliar devices and abnormal Graph API activity.
  • Restrict device-code authentication where it is not required and apply conditional-access policies to unmanaged devices.

Microsoft linked portions of the activity to several tracked threat clusters, while noting that shared phishing infrastructure and tactics make definitive attribution difficult.