Find notable cyber news and cases, enriched with sources, timelines, and signals.

ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 365 data and connected cloud access across multiple organizations. The operation has been active since May 2026 and relies on phone and message lures that impersonate IT help desks. Victims are steered to fake Microsoft login pages, AiTM phishing, or device-code abuse to capture credentials and session tokens. Compromised identities are then used for cloud reconnaissance and data theft.

Related Happenings

CISA and NIST release IR 8587 cloud identity guidance

Public Sector Action
H score27 First: 15.09.2026 15:00 Last: 15.09.2026 15:00 Sources 1

About this happening: CISA and NIST released IR 8587 to guide federal agencies and cloud service providers on protecting tokens and assertions from forgery, theft, and misuse. T...

Microsoft dual phishing campaigns using CEO impersonation and passkey lures

Campaign
H score34 First: 13.09.2026 13:11 Last: 13.09.2026 13:11 Sources 1

About this happening: Microsoft disclosed two coordinated phishing campaigns that used third-party email delivery infrastructure and passkey-themed social engineering to target U.S. enter...

Greatness PhaaS expands into device code phishing and integrated token-theft operations

Threat Actor Meta
H score40 First: 04.08.2026 20:27 Last: 04.08.2026 20:27 Sources 1

About this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...

ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations

Campaign
H score34 First: 29.07.2026 20:54 Last: 29.07.2026 20:54 Sources 1

About this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...

Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA

Security Tool/Service
H score26 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...

Timeline

  1. 11.09.2026 20:26 2 articles · 10d ago

    ShinyHunters- and Helix-linked passkey phishing targets Microsoft 365 accounts

    Initial Disclosure

    Microsoft says threat actors linked to ShinyHunters, Helix, Storm-3121, and Storm-3032 are using passkey- and single sign-on-themed social engineering against corporate Microsoft accounts, steering employees to fake Microsoft login pages or device-code prompts to capture credentials and session tokens. After compromise, the attackers use Microsoft Graph for reconnaissance, add MFA methods they control, and collect data from Microsoft 365 resources including SharePoint Online, OneDrive for Business, Outlook Web, and Microsoft Exchange Online.

    Show sources