Executive Summary

In September 2026, Microsoft Security Research documented a sophisticated cloud-based intrusion campaign targeting Microsoft 365 environments through passkey-themed social engineering attacks. Threat actors, including Storm-3121 and Storm-3032, initiated contact via phone calls and SMS messages, directing victims to convincing phishing sites that captured credentials and session tokens through adversary-in-the-middle (AiTM) techniques. Following initial compromise, attackers established persistence by registering unauthorized MFA methods, conducted extensive reconnaissance using Microsoft Graph APIs, and performed high-volume data exfiltration from SharePoint, OneDrive, and Exchange Online repositories over sustained periods spanning hours to days.

This campaign represents a significant evolution in identity-focused attacks, demonstrating how threat actors exploit trust in emerging authentication technologies like passkeys to bypass traditional security controls and establish persistent cloud access.

Why This Matters Now

Identity-based attacks targeting cloud environments have surged 300% in 2026, with passkey-themed social engineering becoming the preferred initial access vector for ransomware groups and data extortion operators seeking to bypass traditional MFA protections.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers used adversary-in-the-middle (AiTM) phishing and device code authentication flows to capture session tokens and credentials, then registered their own MFA devices to establish persistent access.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain this Microsoft 365-focused attack by limiting lateral movement paths and reducing blast radius through identity-aware segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Identity-aware segmentation policies would likely reduce the scope of initial access by constraining which cloud services and resources compromised accounts could reach from external entry points.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation policies would likely constrain the blast radius of compromised accounts by restricting access to sensitive administrative functions and limiting which identity management operations could be performed.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely reduce lateral access paths between Microsoft 365 services by enforcing segmentation boundaries that limit cross-service token usage and application-to-application communication flows.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility controls would likely reduce the effectiveness of rotating proxy infrastructure by providing consistent monitoring and policy enforcement across cloud service interactions and API usage patterns.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely constrain bulk data extraction by limiting outbound data flows and enforcing transfer restrictions that reduce the volume and scope of automated collection operations.

Impact (Mitigations)

The scope of compromised data and affected business operations would likely be substantially reduced, limiting the attacker's ability to access critical assets and reducing potential extortion leverage.

Impact at a Glance

Affected Business Functions

  • Cloud Identity Management
  • Email and Collaboration Services
  • Document Management and SharePoint
  • Enterprise Data Governance
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $150,000

Data Exposure

Large-scale data exfiltration from Microsoft 365 workloads including SharePoint Online documents, OneDrive business files, and Exchange Online email content. High-volume automated collection spanning multiple user accounts with potential exposure of sensitive organizational data, business communications, and proprietary documents through Microsoft Graph API abuse.

Recommended Actions

  • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement between cloud resources and enforce least privilege access controls
  • Deploy Egress Security & Policy Enforcement to detect and block unauthorized outbound data transfers, including python-httpx automation and high-volume API activities
  • Enable Multicloud Visibility & Control with centralized monitoring to detect anomalous Microsoft Graph API reconnaissance patterns and repeated malformed requests
  • Establish Threat Detection & Anomaly Response capabilities to baseline normal user behavior and alert on covert remote access tools like device code flows
  • Enforce Encrypted Traffic controls for all data in transit and implement comprehensive logging of API activities across SharePoint, OneDrive, and Exchange services

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image