Executive Summary

Since May 2026, threat actors linked to ShinyHunters, Helix, and other extortion gangs have been conducting sophisticated passkey-themed phishing campaigns targeting corporate Microsoft 365 accounts. The attacks begin with extensive pre-attack reconnaissance, followed by social engineering calls impersonating IT help desks to trick employees into urgently updating passkey or MFA configurations. Victims are directed to adversary-in-the-middle phishing sites or device-code authentication flows, allowing attackers to capture credentials and session tokens. Once inside Microsoft cloud environments, attackers perform systematic reconnaissance using Microsoft Graph APIs, establish persistence through MFA method registration, and conduct automated data exfiltration from SharePoint, OneDrive, and Exchange over periods spanning hours to days while avoiding detection. The attacks demonstrate the evolving threat landscape where modern authentication methods like passkeys are weaponized as social engineering lures, highlighting the critical need for phishing-resistant MFA implementations and enhanced cloud security controls in enterprise environments.

Why This Matters Now

This campaign represents a significant evolution in social engineering tactics, weaponizing modern security concepts like passkeys to bypass traditional security awareness. With hybrid work environments increasing reliance on cloud services and identity-based access, these attacks expose critical gaps in enterprise identity protection and highlight the urgent need for phishing-resistant authentication methods.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

These attacks exploit modern security concepts as social engineering lures, using urgency around passkey updates to trick victims into compromising their accounts through legitimate-appearing authentication flows.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the scope and impact of this Microsoft 365 compromise by constraining lateral movement paths and limiting access to cloud resources through segmented workload isolation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: CNSF visibility and monitoring capabilities would likely detect anomalous authentication patterns and suspicious session token usage, potentially alerting security teams to the compromised accounts earlier in the attack sequence.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust segmentation policies would likely constrain the scope of compromised account access by limiting which cloud resources and services the attacker could reach, reducing their ability to establish persistent foothold across multiple systems.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic security controls would likely limit the attacker's reachability across the multi-cloud SSO ecosystem by enforcing segmentation policies between different cloud services and applications, reducing their lateral movement capabilities.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls would likely detect abnormal API usage patterns and automated reconnaissance activities across cloud services, potentially identifying the malicious Graph API calls and Node.js automation tools used for command and control.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security policies would likely constrain the volume and types of data that could be extracted from SharePoint, OneDrive, and Exchange Online by enforcing data loss prevention controls and monitoring abnormal download patterns from cloud storage services.

Impact (Mitigations)

While some data exposure would likely still occur, the overall impact scope would be reduced through constrained lateral movement and limited egress capabilities, potentially reducing the volume of compromised corporate documents and email content available for extortion activities.

Impact at a Glance

Affected Business Functions

  • Email Communication Systems
  • Document Collaboration Platforms
  • Single Sign-On Authentication
  • Cloud Data Storage
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $75,000

Data Exposure

Corporate Microsoft 365 data including SharePoint documents, OneDrive files, Exchange emails and attachments, organizational user information, directory roles and privileged accounts, OAuth permissions, and authentication methods. Attackers performed systematic data collection over multiple hours to days accessing fewer than 1000 files per hour to avoid detection.

Recommended Actions

  • Implement Zero Trust Segmentation to prevent lateral movement between SSO-connected applications and limit blast radius from compromised accounts
  • Deploy Egress Security & Policy Enforcement to detect and block automated data exfiltration patterns and unauthorized data transfers to external destinations
  • Enable Multicloud Visibility & Control to detect suspicious Microsoft Graph API enumeration patterns and automated reconnaissance activities across cloud resources
  • Configure Threat Detection & Anomaly Response to identify unusual sign-in patterns followed by rapid MFA registrations and systematic file access behaviors
  • Enforce phishing-resistant MFA and disable device-code authentication flows when not required, while implementing Cloud Firewall controls to block access to known phishing infrastructure

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image