Cookie Consent by Free Privacy Policy Generator

Microsoft warns of passkey-themed phishing and large-scale financial fraud campaigns

Microsoft has disclosed two phishing campaigns targeting cloud environments and business users. The Hacker News and Dark Reading report that the first campaign involved over one million scam emails sent between 3 and 5 August 2026, impersonating chief executives and using third-party email delivery infrastructure to bypass traditional email security controls. The second campaign used passkey-themed social engineering to trick users into granting access to Microsoft cloud accounts, allowing attackers to exfiltrate data. Both campaigns demonstrate how attackers are adapting their techniques to exploit trust in legitimate platforms and emerging authentication methods. The scale of the first campaign is notable: over one million emails in just three days suggests a high degree of automation and coordination.

Why this matters for UK organisations

The use of third-party email infrastructure to deliver phishing at scale is a growing concern for UK organisations, particularly those relying on Microsoft 365 for collaboration and productivity. Attackers are increasingly using legitimate email services, marketing platforms and transactional email providers to send phishing messages, making it harder for traditional email security controls to identify and block malicious content. The passkey-themed phishing is especially notable because passkeys are being promoted as a more secure alternative to passwords, and attackers are already exploiting user unfamiliarity with how they work. For many organisations, this highlights the gap between deploying new authentication technologies and ensuring that users understand how to recognise and respond to social engineering attempts that misuse them. The operational impact is clear: even modern authentication methods require user awareness and organisational vigilance to remain effective. The financial fraud campaign impersonating chief executives also reflects a continuing trend of business email compromise attacks that rely on authority and urgency to bypass normal approval processes.

What to review

Organisations should review email security controls, particularly how third-party sending infrastructure is handled and whether email authentication standards such as SPF, DKIM and DMARC are properly configured and enforced. Consider whether your email security solution is capable of detecting phishing that originates from legitimate email services. For user awareness, ensure that training reflects current phishing techniques, including passkey-themed social engineering, and that users understand what legitimate authentication prompts look like and how to report suspicious requests. Organisations deploying passkeys or other modern authentication methods should provide clear guidance on how these technologies work and what users should expect during normal authentication flows. Finally, review business email compromise controls, including whether financial approval processes require out-of-band verification and whether users are trained to recognise impersonation attempts, even when they appear to come from senior executives.

Source: The Hacker News

News and blog posts
Today's stories share a common thread: the importance of maintaining...
The US Cybersecurity and Infrastructure Security Agency (CISA) has added five...
Microsoft has disclosed two phishing campaigns targeting cloud environments and...
A study by Syskit, reported by Infosecurity Magazine, has found that only 43%...