Executive Summary
Between May and September 2026, threat actors including Storm-3121 and Storm-3032 conducted sophisticated social engineering campaigns targeting Microsoft cloud environments. The attacks involved AI-assisted executive impersonation for invoice fraud, sending over one million scam emails in August 2026, and passkey-themed phishing operations. Attackers impersonated IT help desk personnel to trick employees into updating authentication methods through fraudulent websites, enabling adversary-in-the-middle attacks and device code authentication bypasses. Once successful, threat actors established persistent access by registering their own MFA methods and conducted extensive data exfiltration through Microsoft Graph API abuse, SharePoint downloads, and mailbox collection. This incident demonstrates the evolution of identity-focused attacks targeting cloud infrastructure and the increasing sophistication of social engineering tactics combined with legitimate cloud service abuse.
Why This Matters Now
This attack pattern represents a critical shift toward identity-focused cloud compromise at scale, exploiting the widespread adoption of passkey authentication and remote work dependencies on cloud services, requiring immediate reassessment of identity verification processes.
Attack Path Analysis
Attackers used passkey-themed social engineering via voice phishing to trick employees into compromising their Microsoft cloud accounts through adversary-in-the-middle authentication flows. Once access was established, threat actors registered their own MFA methods to maintain persistence, then conducted extensive reconnaissance using Microsoft Graph API to enumerate users, resources, and permissions. The attackers performed high-volume data collection from SharePoint Online, OneDrive, and Exchange Online mailboxes through REST APIs, exfiltrating sensitive organizational data over multiple days while rotating infrastructure to evade detection.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors conducted voice phishing campaigns targeting employees' personal phones, impersonating IT helpdesk staff to redirect victims to counterfeit Microsoft sign-in pages for passkey updates, using adversary-in-the-middle and device-code authentication flows to capture credentials
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Multi-Factor Authentication Request Generation
Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay
Valid Accounts: Cloud Accounts
Modify Authentication Process: Multi-Factor Authentication
Steal Application Access Token
Data from Information Repositories: SharePoint
Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication for All Access
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
CISA ZTMM 2.0 – Identity Verification and Authentication
Control ID: ID.AM-2
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Information Security Awareness, Education and Training
Control ID: A.8.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
High risk from passkey phishing targeting Microsoft cloud accounts, enabling ACH fraud and data exfiltration through compromised finance personnel credentials.
Information Technology/IT
Critical exposure to social engineering attacks impersonating IT helpdesk, leading to Microsoft Graph abuse and systematic cloud environment compromise.
Consumer Goods
Vulnerable to AI-assisted executive impersonation targeting accounts payable departments, with fraudulent ServiceNow invoices bypassing traditional financial controls.
Real Estate/Mortgage
Susceptible to CEO impersonation fraud campaigns and cloud identity compromise affecting sensitive financial transactions and client data protection.
Sources
- Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Datahttps://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.htmlVerified
- Microsoft Security Blog - Protecting organizations from AI-assisted executive impersonation and invoice fraudhttps://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/Verified
- Microsoft Security Blog - Passkey-themed social engineering leads to identity and cloud compromisehttps://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/Verified
- Microsoft Learn - Authentication methods activityhttps://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-methods-activityVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain the Microsoft cloud breach by enforcing segmented access controls and restricting lateral movement paths. The attack's blast radius across SharePoint, OneDrive, and Exchange services would likely be reduced through identity-aware access controls and controlled egress enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust CNSF may constrain the scope of initial cloud service access by enforcing identity-aware routing and workload isolation, potentially limiting which Microsoft cloud resources become immediately available to compromised credentials.
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation could limit the privileges and access scope available to compromised accounts, potentially constraining the attacker's ability to expand permissions across multiple Microsoft cloud services and administrative functions.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain lateral movement between Microsoft cloud services by restricting cross-service API communications and limiting the reachability of Graph API enumeration across SharePoint, OneDrive, and Exchange resources.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls may constrain command and control communications by providing enhanced monitoring of Graph API usage patterns and restricting the network paths available for rotating infrastructure across authentication and reconnaissance activities.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely constrain high-volume data exfiltration by enforcing controlled outbound paths and data transfer policies that limit the scope and rate of REST API data collection activities across Microsoft cloud services.
The overall impact scope would likely be reduced through constrained access paths and limited blast radius, though some exposure of accessible data within segmented boundaries may still occur despite Zero Trust controls.
Impact at a Glance
Affected Business Functions
- Email Communications
- Financial Operations
- Data Management
- Identity and Access Management
Estimated downtime: 3 days
Estimated loss: $250,000
Compromise of Microsoft cloud accounts leading to exfiltration of SharePoint and OneDrive business documents, Exchange mailbox contents including emails and attachments, and potential access to sensitive corporate communications and financial records across multiple enterprise organizations
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent unauthorized cross-service access even with compromised credentials
- • Deploy Multicloud Visibility & Control capabilities to detect anomalous Microsoft Graph API usage patterns and high-volume data access behaviors
- • Establish Egress Security & Policy Enforcement to monitor and control outbound data transfers from cloud services to unauthorized destinations
- • Enable Threat Detection & Anomaly Response systems to baseline normal user behavior and alert on suspicious authentication patterns and MFA enrollment activities
- • Strengthen Cloud Native Security Fabric (CNSF) controls to provide real-time inspection and policy enforcement across all cloud service interactions and API calls



