Microsoft Cloud accounts stolen in highly complex impersonation and passkey phishing campaign
- Microsoft warns of a sophisticated campaign tricking users into updating passkeys via fake IT calls
- Victims redirected to adversary‑in‑the‑middle sites mimicking Microsoft login to steal access
- Attackers exfiltrate files from SharePoint, OneDrive, and Exchange; phishing‑resistant MFA advised
Passkeys have made stealing passwords obsolete. To work around this change, hackers have started tricking users into authenticating on attacker-controlled computers. This is according to a new report from Microsoft, which says there’s a highly sophisticated campaign currently taking place, with the goal of compromising people’s cloud accounts and stealing as many sensitive files as possible.
The attack starts a lot earlier than what the victim experiences. There is a lot of pre-attack planning and due diligence, in which the threat actors gather as much information about their target as possible. Knowing their place of work, position, and personal phone number is essential.
Once all the pieces are in place, the attack...
Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE