Two coordinated phishing waves hit Microsoft cloud users
In early August 2026, more than a million emails pretended to be CEOs demanding ACH payments for a bogus ServiceNow subscription.
The messages leveraged domains such as service-nowinc.com and domainlify.net, and Microsoft says generative AI helped craft the template.
Passkey‑phishing campaign that sidesteps MFA
Since May 2026, attackers have called or texted victims, posing as IT help‑desk staff and steering them to counterfeit Microsoft sign‑in pages that mimic passkey enrollment.
Compromised accounts immediately show a flurry of Microsoft Graph calls, bulk SharePoint and OneDrive downloads, and mailbox grabs through REST APIs.
Domain list observed in the second wave includes:
- passkeyhelpdesk.com
- secure-passkey.com
- setupmypasskey.com
- add-passkey.com
- integratedsso.com
- oktasession.com
- syncmykey.com
- portalsetuphub.com
Who’s behind the attacks?
Microsoft attributes activity to several groups: Cordial Spider, O-UNC-045, PREY-0058, UNC6671, Storm‑3121 and Storm‑3032.
Storm‑3121 is linked to ShinyHunters and Falcon extortion operations; Storm‑3032 traces back to UNC6671, a descendant of BlackFile now operating under the Helix brand.
Why the focus on Microsoft cloud?
All victim activity revolves around Azure AD‑protected services—Microsoft Graph, SharePoint Online, OneDrive for Business, Exchange Online, and Teams.
Attackers also add their own MFA factors—phone numbers, authenticator apps, OTP tokens—to keep a foothold even after the initial compromise.
Defensive steps for enterprises
- Enforce strict verification of any CEO‑level financial request, especially those arriving via email.
- Block or monitor traffic to the listed spoofed domains; consider DNS‑based sinkholing.
- Deploy conditional access policies that require MFA re‑challenge for passkey enrollment flows.
- Audit Microsoft Graph activity for anomalous high‑volume calls or bulk file downloads.
- Review MFA registrations and purge unknown authenticators from privileged accounts.
- Educate users that legitimate IT help‑desk personnel never ask for credentials over phone or SMS.
