Microsoft Uncovers AI-Driven Financial Fraud and Passkey Social Engineering Campaigns
Microsoft has detailed two sophisticated campaigns leveraging third-party email infrastructure for financial fraud and employing passkey-themed social engineering to infiltrate cloud environments. These attacks highlight an increasing reliance on advanced social engineering tactics, including AI for crafting convincing lures, and underscore the persistent threat to enterprise security.
Cybersecurity researchers at **Microsoft** have exposed two distinct, yet equally insidious, threat campaigns targeting organizations. The first involves a large-scale financial fraud scheme, while the second details cloud-based intrusions facilitated by cunning passkey-themed social engineering.
### AI-Assisted Executive Impersonation for Invoice Fraud
Between August 3 and 5, 2026, a sophisticated financial fraud campaign unleashed over a million scam emails, impersonating CEOs to trick accounts payable departments into initiating fraudulent **Automated Clearing House (ACH)** transfers. The attackers aimed to secure payments for a bogus **ServiceNow** annual subscription.
Evidence suggests the operators behind this campaign utilized generative artificial intelligence (AI) to craft highly convincing email templates and tailored drafts. The primary targets were enterprise users in the U.S., specifically across IT services, consumer goods, real estate, and discrete manufacturing sectors.
"The campaign follows steps before and during the execution of the campaign: threat actors register impersonation domains, send executive-themed payment requests through trusted infrastructure, embed fabricated invoices and supporting conversations, and attempt to convince finance personnel to initiate ACH transfers," stated the **Microsoft Security Research** team.
Unlike traditional invoice scams, this operation layered executive impersonation, vendor branding, fabricated invoices, and counterfeit email threads to create a compelling narrative designed to bypass recipient skepticism. Attackers even embedded the names and email addresses of actual CEOs, CFOs, and presidents from victim organizations into email signatures for added legitimacy.
Bogus domains used in this campaign include:
* service-nowinc[.]com
* domainlify[.]net
### Passkey-Themed Social Engineering Leads to Cloud Compromise
The second campaign, detected since May 2026, focuses on cloud-based intrusions. It begins with suspicious sign-ins, followed by threat actors adding their own authentication methods, engaging in high-volume **Microsoft Graph** activity, and downloading data from **SharePoint** and **OneDrive** via **REST APIs**.

This activity is consistent with "automated collection from compromised cloud identities using proxy-associated infrastructure," **Microsoft** noted. The attack typically starts with identity-focused social engineering, where threat actors contact users via personal phone numbers, posing as IT help desk personnel. They urge users to update their passkey, **Multi-Factor Authentication (MFA)**, or **Single Sign-On (SSO)** configurations to avoid access disruptions.
Victims are then directed to counterfeit websites mimicking the legitimate **Microsoft** sign-in experience via SMS. The ultimate goal is to guide them through **Adversary-in-the-Middle (AitM)** or device-code authentication flows, either capturing credentials or unknowingly granting access to the attacker's behalf.

**Microsoft** observed that attackers conduct extensive pre-attack research, gathering information on employees and organizational structures from public sources. In some instances, compromised accounts are exploited to expand reach by sending similar passkey-themed messages via **Microsoft Teams**.
Threat actors registered domains themed around passkeys, SSO enrollment, and identity verification, often including the target organization's name as a subdomain:
* passkeyhelpdesk[.]com
* secure-passkey[.]com
* setupmypasskey[.]com
* add-passkey[.]com
* integratedsso[.]com
* oktasession[.]com
* syncmykey[.]com
* portalsetuphub[.]com
### Overlaps with Notorious Cybercrime Groups
This modus operandi shows overlaps with a loose-knit cybercrime collective known as **Cordial Spider**, **O-UNC-045**, **PREY-0058**, and **UNC6671**. This group is known for operating multiple public extortion brands and sharing underlying phishing infrastructure.
**Microsoft** attributes the initial access activity to various threat actors, including **Storm-3121** and **Storm-3032**. **Storm-3121** is linked to initial access leading to **ShinyHunters** and **Falcon (CL-CRI-1182)** extortion. **Storm-3032** is **Microsoft's** designation for **UNC6671**, a group that splintered from **BlackFile (CL-CRI-1116)** and now operates under the **Helix** extortion brand.
In one case, attackers performed an anomalous sign-in to **Microsoft Office Home** from an unmanaged device to expand access to **SharePoint Online** and **OneDrive** via the **Graph API**, enumerating sensitive files and internal services.
Another incident involved a passkey lure to launch a device code phishing attack, gaining control of a victim's account without stealing credentials or cookies, thus bypassing **MFA**. A third attack pattern involved using compromised credentials to register their own phone-based MFA method to bypass existing safeguards and conduct reconnaissance and post-exploitation activities.
"Following initial access, the actor's first objective was to transform a temporary compromise into a persistent foothold," **Microsoft** concluded, emphasizing the shift from credential theft to establishing persistent control through MFA enrollment.