Microsoft Exposes Dual Cyber Threats: Generative AI Financial Scams and Passkey-Themed Cloud Intrusions

Microsoft has issued a comprehensive security advisory detailing two distinct, highly sophisticated threat campaigns currently targeting enterprise organizations. The first operation leverages third-party email delivery infrastructure and generative artificial intelligence (AI) to blast millions of sophisticated financial fraud messages. The second campaign deploys targeted, passkey-themed social engineering tactics designed to compromise cloud environments, bypass multi-factor authentication (MFA), and establish persistent footholds within corporate networks.
These revelations underscore a broader, worrying trend in the cybersecurity landscape: threat actors are increasingly abandoning blunt-force attacks in favor of nuanced, highly contextual social engineering. By blending generative AI capabilities with deep reconnaissance and abuse of trusted corporate APIs, modern cybercriminals are systematically lowering the barriers to entry for complex enterprise fraud and identity theft.
AI-Assisted Financial Fraud: The Automated Clearing House Scheme
The first campaign highlighted by Microsoft’s Security Research team centers on massive, automated financial fraud. Between August 3 and August 5, 2026, threat actors weaponized third-party email delivery services to distribute over one million scam messages. The primary targets were accounts payable departments within U.S. enterprises, specifically focusing on critical sectors such as IT services, consumer goods, real estate, and discrete manufacturing.
Rather than relying on generic, easily detectable phishing templates, the operators utilized generative AI tools to draft customized emails tailored to specific recipients. The messages were carefully constructed to impersonate the chief executive officers (CEOs) or presidents of various target companies.

The core objective of the fraud was to trick finance personnel into initiating unauthorized Automated Clearing House (ACH) transfers for a purported ServiceNow annual subscription. To reduce recipient skepticism and eliminate traditional red flags, the campaign utilized a unified narrative structure.
"Unlike traditional invoice scams that rely on a single social engineering lure, this campaign layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative," Microsoft researchers noted in their public disclosure.
The execution of these attacks followed a meticulous methodology:
- Domain Registration: Attackers registered lookalike domains designed to impersonate legitimate executives and trusted vendors.
- Infrastructure Abuse: They routed high-volume emails through legitimate third-party email delivery services to bypass basic reputation filters.
- Contextual Fabrication: They embedded fake invoices alongside forged email threads and supporting conversations to make the payment request appear as though it had already been vetted by executive leadership.
- Signature Mimicry: Threat actors plugged the real names and corporate email addresses of actual CEOs, CFOs, and presidents into the email signatures to solidify the deception.
By combining these elements, the campaign effectively disarmed the critical thinking of finance personnel, turning routine administrative processes into vectors for substantial financial loss.
Passkey-Themed Social Engineering and Cloud Compromise
While the financial fraud campaign focused on immediate monetary theft via email, the second campaign targeted the crown jewels of enterprise infrastructure: cloud identity and access management. Documented by Microsoft since May 2026, this second wave of intrusions focuses on compromising corporate accounts, adding unauthorized authentication methods, and executing high-volume data exfiltration via the Microsoft Graph API, SharePoint, OneDrive, and REST-based mailbox collection.

The attack vector typically begins with targeted voice phishing (vishing) or smishing. Threat actors reach out directly to an employee’s personal phone number, posing as members of the organization’s internal IT help desk. The caller creates a false sense of urgency, claiming that the employee must immediately update their passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to prevent catastrophic access disruptions.
To facilitate the deception, the attackers register malicious domains utilizing themes such as passkey enrollment, account activation, identity verification, and SSO integration. In a clever structural manipulation, they append the target organization’s name as a subdomain—following the pattern <company name>.<malicious domain>.com—to make the phishing URL appear authentic.
Once the unsuspecting employee visits the counterfeit website, the attackers deploy adversary-in-the-middle (AitM) frameworks or device-code authentication flows. This allows them to capture primary credentials or trick the user into granting device access on the attacker’s behalf, effectively bypassing traditional security controls.
Attribution and Overlaps with Extortion Collectives
Microsoft’s analysis connects the initial access infrastructure of these cloud intrusions to a network of known e-crime groups, including Storm-3121 and Storm-3032. The latter designation tracks activity overlapping with a loose-knit cybercrime collective widely known in the threat intelligence community as Cordial Spider, O-UNC-045, PREY-0058, or UNC6671.
UNC6671 has a well-documented history of deploying credential harvesting panels disguised as passkey portals, utilizing victim-specific subdomains to execute precise vishing campaigns. Historically linked to splinter factions of the BlackFile ransomware and extortion group—now operating under the Helix brand—these actors frequently collaborate or share commoditized initial access playbooks. Their overarching goal is often downstream extortion, feeding compromised credentials to operations like ShinyHunters and Falcon (CL-CRI-1182).

Persistence Mechanics and Microsoft Graph Abuse
Once threat actors successfully breach a corporate account through credential theft, device-code manipulation, or passkey exploitation, their immediate priority shifts from initial access to persistence.
Microsoft has identified three primary patterns of post-compromise activity:
- Unmanaged Device Access: Attackers utilize stolen credentials or anomalous sign-ins to access services like Microsoft Office Home from unmanaged devices, subsequently leveraging the Microsoft Graph API to enumerate internal services, SharePoint Online, and OneDrive repositories.
- Device-Code Phishing Lures: Attackers bypass credential and cookie theft entirely by utilizing passkey pretexts to trick victims into authenticating via device codes, maintaining clean session continuity.
- Secondary MFA Registration: Perhaps the most persistent technique involves the actor registering a secondary, attacker-controlled multi-factor authentication method—such as a new phone number, authenticator application, or software-based one-time password (OTP) token.
By establishing an attacker-controlled second factor, the threat actors can independently sign into the victim’s corporate account at will, even if the primary user changes their password. This persistent foothold allows for quiet, long-term reconnaissance and data collection.
"Following initial access, the actor’s first objective was to transform a temporary compromise into a persistent foothold," Microsoft explained. "Rather than relying solely on stolen credentials, the actor enrolled an MFA method under their control, typically by registering a new phone number, authenticator application, or software-based one-time password token."
Security researchers emphasize that detecting these intrusions presents a unique challenge. Because attackers abuse legitimate administrative interfaces like the Microsoft Graph API, individual API requests rarely appear suspicious in isolation. Cybersecurity teams must analyze cloud activity holistically, focusing on behavioral progression and cross-event correlation rather than reviewing single log entries independently.

Broader Implications and Enterprise Defenses
The dual campaigns disclosed by Microsoft highlight an evolving maturity among modern cybercrime syndicates. By weaponizing generative AI for tailored financial fraud and combining social engineering with the narrative surrounding modern security advancements like passkeys, threat actors are directly exploiting human psychology and administrative trust.
Organizations are advised to reinforce their defenses against these sophisticated threats through several key measures:
- Enhanced Verification Protocols: Accounts payable departments must implement out-of-band verification procedures—such as direct phone calls using pre-established internal numbers—before executing ACH transfers or modifying vendor payment details, regardless of executive approval emails.
- Holistic Cloud Monitoring: Security operations centers (SOCs) should shift from static rule-based alerts to behavioral analytics, closely monitoring Microsoft Graph API calls, unusual SharePoint/OneDrive download spikes, and unauthorized MFA device registrations.
- Phishing-Resistant MFA Enforcement: Enterprises should accelerate the transition toward hardware-backed phishing-resistant MFA (such as FIDO2 security keys) that cannot be intercepted via adversary-in-the-middle phishing panels or device-code manipulation.
- Employee Awareness Training: Training programs must be updated to address modern vishing techniques, specifically warning employees that legitimate IT help desks will never request personal phone verification to update passkeys or SSO configurations under emergency pretexts.
As threat actors continue to refine their automation and social engineering playbooks, the boundary between human error and systemic compromise remains the most critical battleground in enterprise security.







