Executive Summary
Since May 2026, threat actors linked to ShinyHunters, Helix, and other extortion gangs have been conducting sophisticated passkey-themed phishing campaigns targeting corporate Microsoft 365 accounts. The attacks begin with extensive pre-attack reconnaissance, followed by social engineering calls impersonating IT help desks to trick employees into urgently updating passkey or MFA configurations. Victims are directed to adversary-in-the-middle phishing sites or device-code authentication flows, allowing attackers to capture credentials and session tokens. Once inside Microsoft cloud environments, attackers perform systematic reconnaissance using Microsoft Graph APIs, establish persistence through MFA method registration, and conduct automated data exfiltration from SharePoint, OneDrive, and Exchange over periods spanning hours to days while avoiding detection. The attacks demonstrate the evolving threat landscape where modern authentication methods like passkeys are weaponized as social engineering lures, highlighting the critical need for phishing-resistant MFA implementations and enhanced cloud security controls in enterprise environments.
Why This Matters Now
This campaign represents a significant evolution in social engineering tactics, weaponizing modern security concepts like passkeys to bypass traditional security awareness. With hybrid work environments increasing reliance on cloud services and identity-based access, these attacks expose critical gaps in enterprise identity protection and highlight the urgent need for phishing-resistant authentication methods.
Attack Path Analysis
Threat actors linked to ShinyHunters and Helix conducted extensive reconnaissance of target organizations before launching passkey-themed phishing campaigns via phone calls and SMS messages. Victims were tricked into entering credentials on AiTM phishing sites or authorizing device-code authentication, allowing attackers to steal session tokens and bypass MFA. Using compromised accounts, attackers added their own MFA methods for persistence and conducted automated reconnaissance using Microsoft Graph APIs to map cloud resources. Attackers established command and control through legitimate Microsoft 365 APIs and automated tooling with Node.js systems. Data exfiltration occurred over multiple days using automated Python-based tools to access SharePoint, OneDrive, and Exchange Online, downloading organizational documents and email content while avoiding detection through rate limiting. The campaign resulted in significant data theft from multiple organizations and continued access to compromised Microsoft 365 environments for extended periods.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors researched target organizations through social media and professional platforms, then conducted phishing attacks using passkey-themed social engineering via phone calls and SMS. Victims were directed to adversary-in-the-middle (AiTM) phishing sites or tricked into device-code authentication flows to steal credentials and session tokens.
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Multi-Factor Authentication Request Generation
Steal Application Access Token
Valid Accounts: Cloud Accounts
Account Manipulation: Device Registration
Account Discovery: Cloud Account
Email Collection: Remote Email Collection
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
PCI DSS 4.0 – Multi-Factor Authentication for All Access
Control ID: 8.4.2
CISA Zero Trust Maturity Model 2.0 – Identity and Device Trust
Control ID: ID.AM-2
DORA – Identification and Protection
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001:2022 – Identity Management
Control ID: A.5.16
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Microsoft 365 credential harvesting attacks threaten sensitive financial data, regulatory compliance (PCI, HIPAA), and client confidentiality through compromised authentication systems.
Health Care / Life Sciences
Passkey phishing targeting healthcare organizations risks patient data exposure, HIPAA violations, and compromised medical systems through Microsoft 365 data theft.
Capital Markets/Hedge Fund/Private Equity
Previously documented UNC6671 attacks specifically targeted hedge funds using identical passkey social engineering tactics for proprietary financial data exfiltration.
Information Technology/IT
IT sector faces dual risk as both target and attack vector, with compromised Microsoft 365 environments enabling lateral movement to client systems.
Sources
- Passkey-themed phishing attacks lead to Microsoft 365 data thefthttps://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/Verified
- Microsoft Security Blog - Adversary-in-the-middle phishinghttps://www.microsoft.com/en-us/security/blog/Verified
- Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion grouphttps://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/Verified
- Google Threat Intelligence UNC6671 Analysishttps://cloud.google.com/security/threat-intelligenceVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the scope and impact of this Microsoft 365 compromise by constraining lateral movement paths and limiting access to cloud resources through segmented workload isolation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: CNSF visibility and monitoring capabilities would likely detect anomalous authentication patterns and suspicious session token usage, potentially alerting security teams to the compromised accounts earlier in the attack sequence.
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation policies would likely constrain the scope of compromised account access by limiting which cloud resources and services the attacker could reach, reducing their ability to establish persistent foothold across multiple systems.
Control: East-West Traffic Security
Mitigation: East-west traffic security controls would likely limit the attacker's reachability across the multi-cloud SSO ecosystem by enforcing segmentation policies between different cloud services and applications, reducing their lateral movement capabilities.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely detect abnormal API usage patterns and automated reconnaissance activities across cloud services, potentially identifying the malicious Graph API calls and Node.js automation tools used for command and control.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely constrain the volume and types of data that could be extracted from SharePoint, OneDrive, and Exchange Online by enforcing data loss prevention controls and monitoring abnormal download patterns from cloud storage services.
While some data exposure would likely still occur, the overall impact scope would be reduced through constrained lateral movement and limited egress capabilities, potentially reducing the volume of compromised corporate documents and email content available for extortion activities.
Impact at a Glance
Affected Business Functions
- Email Communication Systems
- Document Collaboration Platforms
- Single Sign-On Authentication
- Cloud Data Storage
Estimated downtime: 3 days
Estimated loss: $75,000
Corporate Microsoft 365 data including SharePoint documents, OneDrive files, Exchange emails and attachments, organizational user information, directory roles and privileged accounts, OAuth permissions, and authentication methods. Attackers performed systematic data collection over multiple hours to days accessing fewer than 1000 files per hour to avoid detection.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between SSO-connected applications and limit blast radius from compromised accounts
- • Deploy Egress Security & Policy Enforcement to detect and block automated data exfiltration patterns and unauthorized data transfers to external destinations
- • Enable Multicloud Visibility & Control to detect suspicious Microsoft Graph API enumeration patterns and automated reconnaissance activities across cloud resources
- • Configure Threat Detection & Anomaly Response to identify unusual sign-in patterns followed by rapid MFA registrations and systematic file access behaviors
- • Enforce phishing-resistant MFA and disable device-code authentication flows when not required, while implementing Cloud Firewall controls to block access to known phishing infrastructure



