Microsoft 365 hit by passkey-themed helpdesk vishing tied to ShinyHunters-linked actors, alongside 29,785-email Direct Send spoofing campaign
Microsoft attributes Microsoft 365 cloud intrusions running since May 2026 to Storm-3121 (linked to ShinyHunters and Falcon) and Storm-3032 (BlackFile members now operating as Helix), who impersonate IT help desks by phone and SMS with fake passkey/MFA/SSO…
Multiple outlets describe a converging set of Microsoft 365 threats. Dark Reading reported that voice-based social engineering in BYOD contexts is being used to reach Microsoft 365 corporate data, with Microsoft Graph API used to enumerate compromised tenants and identify lucrative targets, and access then handed to extortion groups including ShinyHunters. Microsoft Security Research (via CSO Online and BleepingComputer) has tracked the campaign since May 2026 and attributes it to Storm-3121, linked to ShinyHunters and Falcon, and Storm-3032, tied to BlackFile members now operating as Helix; Google Threat Intelligence tracks related activity as UNC6671, connected to the BlackFile, Helix, Falcon, Pink, and Redact extortion gangs. Attackers call employees' personal mobile numbers posing as IT help desk staff, urging fake passkey, MFA, or SSO updates that route victims to adversary-in-the-middle phishing pages or device-code authentication flows, yielding credentials, session tokens, and OAuth tokens that exposed Salesforce, Slack, Dropbox, and other SSO apps. Persistence is established by registering attacker-controlled phone, authenticator, and software OTP MFA methods; Microsoft Graph is used to enumerate users, SharePoint, and OAuth grants; and stolen data comes from SharePoint, OneDrive, and Exchange Online, with exfiltration throttled below 1,000 files/emails per hour and automation observed via a python-httpx user agent. Compromised sessions reached OfficeHome, SharePoint Online, Outlook Web, and internal applications within minutes. In a distinct, unattributed vector, KnowBe4 Threat Lab observed 29,785 confirmed phishing emails between July and August 2026 abusing Microsoft 365's Direct Send feature to spoof trusted internal addresses such as HR or accounting by connecting directly to Exchange Online MX endpoints; activity peaked Monday-Tuesday during US Eastern business hours with near-zero weekend volume, about 35% of messages carried malicious attachments (fake invoices, voicemail alerts, OneDrive shares), and 4,023 used cross-domain reply-to addresses. Recommended mitigations include phishing-resistant MFA, Conditional Access, and blocking device-code flows for the vishing campaign, and DMARC p=reject, connector allowlists, DKIM signing, and checks for the 'X-MS-Exchange-Organization-AuthAs: Anonymous' header for Direct Send abuse.
- Microsoft has tracked the M365 intrusion campaign since May 2026, attributing it to Storm-3121 (linked to ShinyHunters and Falcon) and Storm-3032 (tied to BlackFile members now operating as Helix); Google Threat Intelligence tracks related…
- Attackers impersonate corporate IT help desks by phone or SMS, calling victims' personal mobile numbers with fake passkey, MFA, or SSO enrollment requests that lead to AiTM phishing pages or device-code authentication flows harvesting…
- Device-code phishing issued OAuth tokens to attacker-controlled apps, exposing Salesforce, Slack, Dropbox, and other SSO applications; the passkey standard itself was not broken - phishable MFA was the bypassed factor.
- Persistence is achieved by registering attacker-controlled phone, authenticator, and software OTP MFA methods; Microsoft Graph is used to enumerate users, SharePoint, and OAuth grants, and compromised sessions accessed OfficeHome,…
- Data was stolen from SharePoint, OneDrive, and Exchange Online with exfiltration throttled below 1,000 files/emails per hour; high-volume SharePoint/OneDrive activity showed automation via a python-httpx user agent.
- Dark Reading reports access is subsequently passed to extortion groups including ShinyHunters, and that BYOD-permitting organizations face heightened exposure to voice-led account takeover.
- KnowBe4 Threat Lab observed 29,785 confirmed phishing emails between July and August 2026 abusing M365 Direct Send to spoof internal senders such as HR or accounting by connecting directly to Exchange Online MX endpoints and bypassing…
- The Direct Send campaign peaked Monday-Tuesday during US Eastern business hours with near-zero weekend volume; about 35% of messages carried malicious attachments (fake invoices, voicemail alerts, OneDrive shares) and 4,023 used…
Coverage timelineoldest first · each row is one article
- · 6d agoVoice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Dark Reading· 70
Threat actors use voice calls and Microsoft Graph API via BYOD devices to access Microsoft 365, then sell access to extortion groups like ShinyHunters.
- · 6d agoAttackers use passkey-themed scams to hijack Microsoft 365 accounts
CSO Online· 78
Microsoft tracks ongoing M365 cloud intrusions since May using passkey-themed helpdesk vishing, AiTM phishing, and device-code abuse.
- · 6d agoHackers Favor US Eastern Business Hours in M365 Phishing Campaign
Infosecurity Magazine· 58
KnowBe4 tracked 29,785 phishing emails abusing Microsoft 365 Direct Send to spoof internal senders while timing sends to US Eastern business hours.
- · 5d agoPasskey-themed phishing attacks lead to Microsoft 365 data theft
BleepingComputer· 78
Microsoft links ShinyHunters- and Helix-affiliated actors to passkey-themed vishing and device-code phishing that compromises Microsoft 365 accounts and steals cloud data.