Attackers Exploit Passkey Phishing to Compromise Microsoft Cloud Accounts
Microsoft reports two campaigns using third‑party email services and passkey‑themed social engineering to deliver fraud scams and hijack cloud accounts, highlighting rising threats for Australian IT professionals.
Written and published by the Wepro Technology team
Microsoft has disclosed two coordinated phishing campaigns that target its cloud services, employing sophisticated tactics that include abusing third‑party email delivery infrastructure to send large‑scale financial fraud messages and leveraging passkey‑related social engineering to gain unauthorized access.
The first operation involved more than a million scam emails dispatched between 3 and 5 August 2026, with attackers impersonating chief executive officers to increase credibility and lure recipients into revealing credentials or authorising payments.
The second campaign focuses on the growing adoption of passkeys, using fake prompts and messages that appear to be legitimate Microsoft notifications, tricking users into approving authentication requests and thereby granting threat actors footholds within Azure and Office 365 environments.
Australian organisations are urged to review their email filtering, multi‑factor authentication policies, and user education programmes, as the tactics mirror local phishing trends that have previously targeted government and corporate sectors across the country.
Professionals seeking to bolster their defensive skills can consider specialised training such as the Security+ certification offered by Wepro Technology, which covers modern threat vectors and best practices for protecting cloud workloads.
Stay ahead in IT
Join 200+ Australian IT professionals getting weekly insights delivered to their inbox.
- Weekly IT news & insights
- New course announcements
- Free quiz updates
Your email
No spam, ever · Unsubscribe anytime