Passkey-Themed Social Engineering Campaign Targeting Cloud Identities and SaaS Data
Published on 14-Sep-2026 14:30:00
Executive Summary
BGD e-GOV CIRT is issuing this advisory regarding an active social-engineering campaign in which threat actors use passkey, MFA, SSO and identity-verification themes to compromise cloud identities and subsequently access organizational cloud resources.
The campaign is particularly significant because the passkey itself is not the vulnerability. Instead, threat actors use the promise of passkey enrollment or MFA configuration as a social-engineering pretext. Victims may receive a phone call or message from an individual impersonating an internal IT/helpdesk employee and are instructed to complete an urgent authentication or passkey-registration process. The victim is then redirected to an attacker-controlled authentication page or instructed to complete a legitimate device-code authentication process.
Microsoft has observed multiple attack paths involving adversary-in-the-middle (AiTM) phishing, device-code phishing, stolen session/token replay, and previously registered attacker-controlled MFA methods. Following successful identity compromise, actors register their own authentication method, conduct Microsoft Graph reconnaissance, enumerate users, groups, roles, applications, SharePoint/OneDrive repositories and mailboxes, and subsequently perform sustained collection of cloud-hosted files and email.
The campaign demonstrates a shift from conventional endpoint-centric intrusion toward identity-centric cloud compromise. No malware installation or traditional network lateral movement is necessarily required. A compromised cloud identity can provide direct access to email, documents, collaboration platforms and other SaaS applications.
Microsoft reports that the activity has been observed since May 2026 and assesses that the initial-access activity is used by multiple threat actors, including clusters tracked as Storm-3121 and Storm-3032, among others. Attribution should therefore not be generalized to a single actor.
Threat Overview
The campaign follows an identity-to-cloud attack lifecycle:
Figure: Passkey-Themed Social Engineering to Cloud Identity Compromise and Data Collection
Microsoft's observed sequence specifically links unusual sign-ins with new authentication-method registration, Graph reconnaissance, SharePoint/OneDrive access and email collection.
Significance of the Campaign
Traditional phishing investigations frequently focus on:
· malicious URLs;
· malicious attachments;
· endpoint malware;
· suspicious processes;
· command-and-control infrastructure.
This campaign can bypass much of that visibility. A successful attack may involve:
· A phone call to the victim's personal number.
· An SMS or collaboration message.
· A browser session.
· A legitimate cloud authentication page.
· A legitimate authentication token.
· A legitimate cloud identity.
· Legitimate cloud APIs.
Consequently, endpoint malware may never be installed.
When a victim uses a personal mobile device that is not covered by enterprise endpoint telemetry, the initial phishing interaction may produce little or no endpoint evidence. The victim's recollection of the phone call or message may become an important initial forensic clue.
Initial Access — Passkey-Themed Social Engineering
Helpdesk impersonation:
The attack commonly begins with an attacker impersonating:
· IT helpdesk personnel;
· identity-management personnel;
· system administrators;
· security teams;
· technical support staff.
The victim is told that an authentication-related change is urgently required. Common pretexts include:
· Passkey enrollment required
· MFA migration required
· SSO configuration update
· Account verification required
· Authentication synchronization required
· Security registration required
Full Advisory is attached Below