Microsoft Discloses Phishing Campaigns Targeting Cloud Environments and Email Inboxes
Microsoft has disclosed two campaigns of phishing attacks targeting cloud environments and email inboxes. In the first campaign, attackers sent over a million scam emails between August 3-5, masquerading as CEOs of target companies to persuade accounts payable departments to initiate ACH transfers for a ServiceNow subscription.
The emails used generative AI to create templates and tailored drafts. They contained fabricated invoices and supporting conversations, aiming to reduce recipient skepticism.
In the second campaign, threat actors used passkey-themed social engineering to breach cloud environments. They called or messaged users' personal phone numbers, claiming to be from the organization's IT help desk, to update their passkeys or MFA configuration.
The attackers then redirected users to counterfeit websites mimicking the Microsoft sign-in experience via SMS messages, guiding them through AitM or device-code authentication flows. This allowed them to capture credentials or gain control of accounts without stealing passwords or cookies.