[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqUciByB3ZZqk2hyLx3IdFmQj1f9ffyQR9CZoyi7W0sA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"dbe8fe4b-912b-46db-bbc5-57bc3e8494b4","passkey-phishing-and-ceo-impersonation-target-microsoft-cloud-accounts","6c63d43d-c7cd-4a42-b227-74c40f3fee23","Passkey Phishing and CEO Impersonation Target Microsoft Cloud Accounts","Attackers are exploiting user trust through two sophisticated social engineering campaigns: AI-generated CEO impersonation emails targeting finance teams for fraudulent wire transfers, and passkey-themed phishing luring users into compromising their Microsoft cloud credentials. The root issue is that employees lack the awareness to distinguish legitimate authentication requests from convincing fakes, even when modern passkey technology is referenced to appear credible. Once cloud accounts are compromised, attackers move quickly to exfiltrate sensitive data before detection. This matters because AI-enhanced phishing dramatically lowers the skill barrier for attackers while raising the believability of attacks, making human judgment alone an insufficient defense.","**Immediate actions:**\n- Deploy phishing-resistant MFA (e.g., FIDO2 hardware keys) across all Microsoft cloud accounts, replacing SMS or app-push methods.\n- Brief finance and executive-adjacent teams immediately on AI-generated CEO impersonation tactics and require out-of-band verbal confirmation for all ACH or wire transfer requests.\n- Audit Microsoft 365 OAuth app permissions and revoke any unrecognized or overly permissive third-party app consents.\n\n**Long-term improvements:**\n- Implement a Zero Trust access model with conditional access policies that restrict cloud account logins based on device compliance, location, and risk score.\n- Establish a formal Security Awareness Training program with quarterly simulated phishing exercises that include passkey and MFA-themed lures.\n- Apply the principle of least privilege to all cloud accounts, ensuring users only have access to data necessary for their role.\n\n**Detection measures:**\n- Enable Microsoft Defender for Cloud Apps (or equivalent CASB) to alert on anomalous data access, bulk downloads, or impossible-travel login events.\n- Configure SIEM rules to detect large-volume data exfiltration patterns from Microsoft 365 services such as SharePoint, OneDrive, and Exchange.\n- Monitor and alert on new mail forwarding rules or inbox delegation changes, which are common attacker persistence techniques after account compromise.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"CIS Control 4 – Secure Configuration of Enterprise Assets","CIS Control 6 – Access Control Management","CIS Control 14 – Security Awareness and Skills Training","CIS Control 17 – Incident Response Management","NIST SP 800-63B – Digital Identity Guidelines (Phishing-Resistant AAL3)","NIST AC-2 – Account Management","NIST AC-6 – Least Privilege","NIST SI-3 – Malicious Code Protection","NIST IR-6 – Incident Reporting","MITRE ATT&CK T1566 – Phishing","MITRE ATT&CK T1530 – Data from Cloud Storage","GDPR Article 32 – Security of Processing","GDPR Article 33 – Notification of Personal Data Breach","published","2026-09-13T12:20:25.418685+00:00","2026-09-13T12:20:25.042+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fattackers-use-passkey-phishing-to.html","attackers-use-passkey-phishing-to-hijack-microsoft-cloud-accounts-and-exfiltrate-fa5906","Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":40,"name":41,"slug":42,"description":43,"color":44},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":46,"name":47,"slug":48,"description":49,"color":50},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[52],{"id":53,"date":54,"edition":55,"title":56,"audio_url":57},"76b9df28-3038-405a-b85c-81c8b0954a42","2026-09-13","afternoon","ThreatNoir Weekend Brief — September 13","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-13\u002Fthreatnoir-afternoon-brief-2026-09-13.mp3"]