ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign
Campaign
Summary
Hide ▲
Show ▼
A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 365 data and connected cloud access across multiple organizations. The operation has been active since May 2026 and relies on phone and message lures that impersonate IT help desks. Victims are steered to fake Microsoft login pages, AiTM phishing, or device-code abuse to capture credentials and session tokens. Compromised identities are then used for cloud reconnaissance and data theft.
Related Happenings
CISA and NIST release IR 8587 cloud identity guidance
Public Sector Action
H score27
First: 15.09.2026 15:00
Last: 15.09.2026 15:00
Sources 1
About this happening:
CISA and NIST released IR 8587 to guide federal agencies and cloud service providers on protecting tokens and assertions from forgery, theft, and misuse. T...
CISA and NIST release IR 8587 cloud identity guidance
Public Sector ActionAbout this happening: CISA and NIST released IR 8587 to guide federal agencies and cloud service providers on protecting tokens and assertions from forgery, theft, and misuse. T...
Microsoft dual phishing campaigns using CEO impersonation and passkey lures
Campaign
H score34
First: 13.09.2026 13:11
Last: 13.09.2026 13:11
Sources 1
About this happening:
Microsoft disclosed two coordinated phishing campaigns that used third-party email delivery infrastructure and passkey-themed social engineering to target U.S. enter...
Microsoft dual phishing campaigns using CEO impersonation and passkey lures
CampaignAbout this happening: Microsoft disclosed two coordinated phishing campaigns that used third-party email delivery infrastructure and passkey-themed social engineering to target U.S. enter...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor Meta
H score40
First: 04.08.2026 20:27
Last: 04.08.2026 20:27
Sources 1
About this happening:
Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor MetaAbout this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
Campaign
H score34
First: 29.07.2026 20:54
Last: 29.07.2026 20:54
Sources 1
About this happening:
The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...
ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
CampaignAbout this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/Service
H score26
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/ServiceAbout this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Timeline
-
11.09.2026 20:26 2 articles · 10d ago
ShinyHunters- and Helix-linked passkey phishing targets Microsoft 365 accounts
Initial DisclosureMicrosoft says threat actors linked to ShinyHunters, Helix, Storm-3121, and Storm-3032 are using passkey- and single sign-on-themed social engineering against corporate Microsoft accounts, steering employees to fake Microsoft login pages or device-code prompts to capture credentials and session tokens. After compromise, the attackers use Microsoft Graph for reconnaissance, add MFA methods they control, and collect data from Microsoft 365 resources including SharePoint Online, OneDrive for Business, Outlook Web, and Microsoft Exchange Online.
Show sources
- Passkey-themed phishing attacks lead to Microsoft 365 data theft — www.bleepingcomputer.com — 11.09.2026 20:26
- Passkey-themed phishing attacks lead to Microsoft 365 data theft — www.bleepingcomputer.com — 11.09.2026 20:26