Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration

Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 (TL-2026-2472) is a high-severity phishing campaign, first published 2026-09-13. It is attributed to Storm-3121 with medium confidence, affects Microsoft Microsoft 365 / Entra ID (Exchange Online, SharePoint, maps to 19 MITRE ATT&CK techniques (T1020, T1069.003, T1070.008), and is covered by 9 detection rules and 29 indicators of compromise.

Key facts for TL-2026-2472

Threat ID
TL-2026-2472
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-09-13
Last reviewed
2026-09-13
Attribution
Storm-3121
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
financial services, private equity, legal services, it services, consumer goods, manufacturing, real estate, health, insurance, technology, hospitality, government administration
Target regions
North America, united states of america, australia, united kingdom
Detection rules
9
Indicators of compromise
29

Malware and tooling in Passkey-Themed Help Desk Phishing Hijacks Microsoft 365

Malware and tooling: Pink, WindowsPowerShell/5.1, python-httpx, python-requests/2.28.1

Storm-3121 and Storm-3032 (UNC6671/Cordial Spider), initial-access brokers feeding the ShinyHunters/BlackFile/Helix/Falcon/Redact/Pink extortion ecosystem, impersonate corporate IT help desks by phone or SMS to trick employees into completing passkey/MFA "migrations" via adversary-in-the-middle or device-code authentication flows, then abuse the Microsoft Graph API to enumerate and mass-exfiltrate SharePoint, OneDrive, and Exchange Online data for extortion. A related campaign sent over one million AI-generated, executive-impersonation invoice-fraud emails between August 3-5, 2026 targeting accounts payable departments.

How Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 works

Since at least May 2026, Microsoft has tracked Storm-3121 and Storm-3032 running a passkey-themed social-engineering campaign against Microsoft 365 tenants. Operators call or text employees on personal mobile devices, impersonating internal IT help desk staff and claiming an urgent, mandatory passkey, MFA, or SSO update is required. Victims are walked through a counterfeit Microsoft sign-in page that stages either an adversary-in-the-middle (AiTM) reverse-proxy phishing flow — capturing credentials and session tokens in real time — or a device-code authentication flow, in which the victim unknowingly authorizes the attacker's device. Storm-3032 is a splinter of the BlackFile extortion brand now operating as Helix; Storm-3121 leads into the ShinyHunters/Falcon extortion pipeline. Both funnel into the same loose-knit UNC6671 (aka Cordial Spider, PREY-0058) cybercrime collective, which has run parallel extortion brands (BlackFile, Redact, Pink, Helix, Falcon) off shared phishing infrastructure and identical templates since emerging in January 2026.

After initial compromise, the actors register attacker-controlled MFA methods (PhoneAppOTP authenticator entries, software tokens tagged 'SoftwareTokenActivated', phone- and email-based MFA) to persist access even if the original credential is reset. They then conduct systematic reconnaissance via the Microsoft Graph API — profiling the tenant (/organization, /subscribedSkus), enumerating directory objects (/users, /groups, /members, /transitiveMembers), mapping privilege (/directoryroles, /roleManagement, /authentication/methods) and applications (/applications, /servicePrincipals, /oauth2PermissionGrants), then pivoting into repository discovery (/sites, /drives, /drive/items, /search) and mailbox enumeration (/messages, /mailFolders, /attachments). Because each individual Graph call resembles legitimate application traffic, Microsoft notes the abuse 'rarely appears suspicious when viewed through a single API call' and requires cross-event correlation to detect. High-volume, automated collection follows — file and email access sustained over hours to multiple days, throttled below roughly 1,000 files/hour to avoid triggering volumetric alerts, frequently using the python-httpx user agent for downloads. The actors deliberately rotate IP infrastructure across the attack lifecycle, using separate source IPs for authentication, reconnaissance, and exfiltration, and route traffic through residential and commercial proxy services. Once data is staged, defense-evasion cleanup follows: password-reset confirmations, security notifications, and MFA-change alert emails are deleted from the victim mailbox to delay detection. Exfiltrated SharePoint, OneDrive, and Exchange data is handed to extortion brands (ShinyHunters, Helix, Falcon, Redact, Pink) for ransom demands; Bitcoin tracing between January 7 and May 12, 2026 alone attributed 141.65 BTC (~$10.69M) in payments to the ecosystem, with initial demands of $1-3M typically settling near $750,000 after negotiation.

A parallel, related campaign run by the same actor ecosystem used generative AI to draft and personalize over one million executive-impersonation invoice-fraud emails sent between August 3-5, 2026, spoofing CEOs and a ServiceNow annual-subscription-renewal pretext to solicit fraudulent ACH payments from U.S. accounts-payable departments, using attacker-registered lookalike domains and fabricated invoice threads. UNC6671's broader targeting has evolved over 2026 from manufacturing, real estate, healthcare, and insurance (April-May) through technology, transportation, and hospitality (June) to financial services, private equity, law firms, and financial rating agencies (July onward), spanning North America, Australia, and the UK.

MITRE ATT&CK techniques used in TL-2026-2472

Exfiltration

T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service

Discovery

T1069.003 Permission Groups Discovery: Cloud Groups; T1087.004 Account Discovery: Cloud Account; T1526 Cloud Service Discovery

Defense Evasion

T1070.008 Indicator Removal: Clear Mailbox Data

Initial Access

T1078.004 Valid Accounts: Cloud Accounts; T1566.004 Phishing: Spearphishing Voice

Collection

T1114.002 Email Collection: Remote Email Collection; T1213.002 Data from Information Repositories: SharePoint; T1530 Data from Cloud Storage

Credential Access

T1528 Steal Application Access Token; T1557 Adversary-in-the-Middle

Persistence

T1556.006 Modify Authentication Process: Multi-Factor Authentication

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1585.002 Establish Accounts: Email Accounts

Reconnaissance

T1591 Gather Victim Org Information; T1598.003 Phishing for Information: Spearphishing Link

Impact

T1657 Financial Theft

Affected products and versions in Passkey-Themed Help Desk Phishing Hijacks Microsoft 365

  • Microsoft — Microsoft 365 / Entra ID (Exchange Online, SharePoint Online, OneDrive for Business)
    Vulnerable versions: Any tenant relying on non-phishing-resistant MFA (SMS, voice, authenticator push, OTP)
    Fixed in: N/A — social-engineering/identity-abuse technique, not a software vulnerability; mitigated via phishing-resistant MFA and Conditional Access enforcement
  • Okta — Okta Identity Cloud
    Vulnerable versions: Tenants without phishing-resistant authentication (Okta FastPass, FIDO2) enforced
    Fixed in: N/A — mitigated via Okta FastPass / phishing-resistant MFA enforcement

Remediation for Passkey-Themed Help Desk Phishing Hijacks Microsoft 365

Immediate actions

  • Revoke active sessions and refresh tokens for any account suspected of compromise
  • Reset credentials and remove all unauthorized/attacker-added authentication methods from affected accounts
  • Remove attacker-created mailbox rules and restore deleted security-notification and MFA-alert emails where possible
  • Alert on and investigate every help-desk-initiated credential or MFA reset request

Workarounds

  • Restrict authentication to trusted corporate network ranges or a SASE platform pending phishing-resistant MFA rollout
  • Train help-desk and IT staff to independently verify any inbound call/SMS claiming to be IT support before performing any credential or MFA action, and train employees to never accept unsolicited passkey/MFA 'update' instructions from phone or SMS contact

Longer-term hardening

  • Enforce phishing-resistant MFA (FIDO2 security keys, platform passkeys, Windows Hello for Business) via Conditional Access
  • Require managed, compliant devices for access to Exchange, SharePoint, and Microsoft Graph
  • Block device-code and authentication-transfer authentication flows tenant-wide unless explicitly required
  • Restrict user consent for OAuth applications; require admin approval for new application registrations
  • Integrate all SaaS applications with centralized SSO (Entra ID/Okta) and enforce daily re-authentication, idle timeouts, and Continuous Access Evaluation
  • Enable Microsoft Graph activity logging and mailbox auditing tenant-wide; deploy the advanced hunting queries published by Microsoft for reconnaissance, MFA-registration, and exfiltration-pattern detection

Timeline of Passkey-Themed Help Desk Phishing Hijacks Microsoft 365

  • Earliest Bitcoin extortion payments to tracked BlackFile-linked wallet addresses begin (Mandiant financial analysis window starts).
  • UNC6671 begins accelerated registration of passkey/SSO-themed phishing root domains, averaging one new domain every 2.2 days through May 31, 2026.
  • Microsoft begins tracking Storm-3121 and Storm-3032 passkey-themed help-desk phishing activity against Microsoft 365 tenants.
  • BlackFile extortion brand publicly announces retirement; ransom payments to its wallets continue afterward, indicating the shutdown was cosmetic.
  • UNC6671 rebrands one operating extortion front as 'Redact', continuing to share infrastructure and vishing scripts with BlackFile/Pink/Helix/Falcon.
  • UNC6671 targeting shifts toward financial services, private equity firms, major law firms, and financial-rating agencies, away from earlier manufacturing/healthcare/hospitality focus.
  • Seven new phishing root domains registered within a 72-hour window (July 20-22, 2026) as part of accelerated infrastructure provisioning.
  • Over one million AI-generated, executive-impersonation invoice-fraud emails sent (August 3-5, 2026) using a ServiceNow subscription-renewal pretext to target U.S. accounts-payable departments.
  • Arctic Wolf's Cordial Spider/PREY-0058 report on IT help-desk vishing for cloud data theft and extortion is published and syndicated via RH-ISAC and Help Net Security.
  • Microsoft Security Blog publishes 'Passkey-themed social engineering leads to identity and cloud compromise,' detailing Storm-3121/Storm-3032 Graph API abuse TTPs and IOCs.
  • The Hacker News publishes consolidated coverage tying the passkey phishing and invoice-fraud campaigns together; threat tracked as TL-2026-2472.

Sources cited for Passkey-Themed Help Desk Phishing Hijacks Microsoft 365

More in phishing

Detection coverage for TL-2026-2472

As of 2026-09-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2472 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2472

13 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats