Microsoft Warns Customers of Cloud Storage Attacks and Email Fraud Scams
Microsoft has issued warnings about two recent social engineering campaigns targeting customers' cloud-based assets and directing fraudulent business transactions over email. The first campaign involves attackers contacting victims by phone, claiming they need to update passkey or multi-factor authentication (MFA) configurations. Victims are then led to a fake login page where their credentials and session tokens are stolen using adversary-in-the-middle (AiTM) techniques.
The second campaign targets employees via email, with attackers impersonating executives such as the CEO or president to convince employees to process Automated Clearing House (ACH) payments totaling nearly $50,000. This scam is suspected to involve the use of generative AI to create convincing fake email threads.
Microsoft noted that both attacks can lead to significant financial loss, as compromised accounts are commonly followed by extortion from groups such as ShinyHunters and Helix. To protect against these attacks, Microsoft recommends enforcing phishing-resistant MFA methods like FIDO2 passkeys or Windows Hello for Business.