Passkey Phishing and CEO Impersonation Target Microsoft Cloud Accounts
Attackers are exploiting user trust through two sophisticated social engineering campaigns: AI-generated CEO impersonation emails targeting finance teams for fraudulent wire transfers, and passkey-themed phishing luring users into compromising their Microsoft cloud credentials. The root issue is that employees lack the awareness to distinguish legitimate authentication requests from convincing fakes, even when modern passkey technology is referenced to appear credible. Once cloud accounts are compromised, attackers move quickly to exfiltrate sensitive data before detection. This matters because AI-enhanced phishing dramatically lowers the skill barrier for attackers while raising the believability of attacks, making human judgment alone an insufficient defense.
Tactical Insight
Immediate actions
- Deploy phishing-resistant MFA (e.g., FIDO2 hardware keys) across all Microsoft cloud accounts, replacing SMS or app-push methods.
- Brief finance and executive-adjacent teams immediately on AI-generated CEO impersonation tactics and require out-of-band verbal confirmation for all ACH or wire transfer requests.
- Audit Microsoft 365 OAuth app permissions and revoke any unrecognized or overly permissive third-party app consents.
Long-term improvements
- Implement a Zero Trust access model with conditional access policies that restrict cloud account logins based on device compliance, location, and risk score.
- Establish a formal Security Awareness Training program with quarterly simulated phishing exercises that include passkey and MFA-themed lures.
- Apply the principle of least privilege to all cloud accounts, ensuring users only have access to data necessary for their role.
Detection measures
- Enable Microsoft Defender for Cloud Apps (or equivalent CASB) to alert on anomalous data access, bulk downloads, or impossible-travel login events.
- Configure SIEM rules to detect large-volume data exfiltration patterns from Microsoft 365 services such as SharePoint, OneDrive, and Exchange.
- Monitor and alert on new mail forwarding rules or inbox delegation changes, which are common attacker persistence techniques after account compromise.