Passkey Phishing Is Quietly Hacking Microsoft Cloud Accounts—Here's How
Michael Miller ·
Listen to this article~4 min
Microsoft reveals two massive phishing campaigns: one sent a million CEO scam emails, the other uses passkey-themed social engineering to breach cloud accounts. Here's what you need to know.
Microsoft just dropped details on two campaigns that should make anyone using cloud accounts sit up straight. Threat actors are getting creative, and the methods they're using are both clever and concerning. Let's break down what's happening and what it means for you.
### The Scam That Hit a Million Inboxes
Between August 3 and 5, 2026, attackers sent over a million scam emails. That's a million messages landing in inboxes across the country, all designed to look like they came straight from the CEO. The goal? Financial fraud. They were masquerading as chief executives to trick employees into sending money or revealing sensitive info. It's the classic business email compromise playbook, but at an enormous scale.
How did they pull it off? By abusing third-party email delivery infrastructure. Instead of setting up their own shady servers, they piggybacked on legitimate services that many companies already trust. That makes the emails harder to flag as suspicious. When the sender looks like a known service provider, people let their guard down.
### Passkey Phishing: The New Kid on the Block
The second campaign is where things get really interesting—and a bit scary. Attackers are using passkey-themed social engineering to breach cloud environments. Passkeys are supposed to be the ultimate security upgrade, right? They're phishing-resistant by design. But here's the catch: if you can trick someone into thinking they're setting up or resetting a passkey, you can still steal their credentials.
It's like someone convincing you to hand over your house key by pretending to be the locksmith. You think you're improving security, but you're actually opening the door for the bad guy.
### Why This Matters for Your Cloud Security
If your organization relies on Microsoft cloud services—and let's face it, most do—these campaigns are a wake-up call. The attackers aren't just brute-forcing their way in. They're using psychology. They're exploiting trust in email infrastructure and the growing familiarity with passkeys.
> "The most sophisticated attacks don't break down the door. They convince you to open it yourself."
That quote sums up the passkey phishing threat perfectly. It's not about hacking software; it's about hacking people.
### What You Can Do to Stay Safe
- **Train your team on passkey phishing.** Make sure everyone knows that legitimate passkey setup never happens through unsolicited emails or links.
- **Verify unusual requests.** If the CEO suddenly asks for a wire transfer, pick up the phone and confirm. Don't rely on email alone.
- **Use email authentication protocols.** DMARC, DKIM, and SPF can help filter out spoofed messages, even when they come through third-party services.
- **Monitor for anomalies.** Unusual login attempts or passkey changes should trigger alerts.
### The Bottom Line
Attackers are evolving. They're combining old tricks like CEO fraud with new angles like passkey phishing. The million-email scam shows they can operate at scale, and the passkey campaign proves they're targeting the very tools we trust for security.
Staying informed is your first line of defense. Share this with your IT team, talk about it in your next security meeting, and double-check every unexpected request. Because in the world of cloud security, a little skepticism goes a long way.