Warning on AI-powered phishing campaign targeting Microsoft Cloud accounts
Microsoft has issued an urgent alert regarding two highly sophisticated cyberattack campaigns targeting enterprise users. Moving away from clumsy email spam tactics, cybercriminals have now integrated Artificial Intelligence (AI) and leveraged requests to "update Passkeys" (login security keys) to steal both money and data. The danger of these AI-powered phishing campaigns lies in their direct targeting of the human factor, psychologically manipulating victims into handing over control themselves.
AI-powered phishing tactics impersonating top executives to steal assets
In early August 2026, a massive attack wave involving over one million phishing emails bombarded US-based companies across the information technology, manufacturing, and real estate sectors. Their goal was to trick accounting departments into executing high-value wire transfers.
To achieve this, hackers leveraged AI to automate the drafting of emails impersonating Chief Executive Officers (CEOs) or senior leadership with exceptionally natural and fluent phrasing.

Beyond spoofing sender names, they forged fake payment invoices from familiar service providers, accompanied by seamlessly spliced email conversations as supporting evidence. By combining the authority of the "boss" with the urgency of invoice payment, scammers dispelled the suspicions of finance staff, urging them to transfer money into attacker-controlled accounts.
Posing as IT support and the Passkey update trap
While the first campaign targeted money, the second aimed directly at internal data storage systems. In this campaign, threat actor groups spent considerable time lurking, gathering personal information and organizational structures of enterprises from social media.
Once a target was identified, they called or sent text messages to victims, posing as the company's Information Technology (IT) support department. Citing system errors, they urged users to immediately update their Passkey or reconfigure Multi-Factor Authentication (MFA) to avoid work disruptions. When victims accessed the spoofed link that mirrored the Microsoft login interface, hackers instantly snatched their credentials. Even more concerning, in several instances, hackers used previously compromised internal accounts to send phishing messages via Microsoft Teams to enhance credibility.
How hackers establish persistence and exfiltrate data on Microsoft Cloud
The most sophisticated aspect of this attack wave is how perpetrators establish a persistent presence inside the system without detection. Instead of relying solely on stolen passwords, they proactively register their own authentication methods under the victim's account, such as adding a new phone number or a One-Time Password (OTP) generator app.

This "spare key" allows them to log into Microsoft Cloud at will, even after the victim changes their password. From there, hackers begin rummaging through the entire system, hunting for accounts with higher administrative privileges. They mass download emails, files, and sensitive data from SharePoint Online and OneDrive. This exfiltration process can span several days. To cover their tracks and bypass firewalls, hackers continuously alter their Internet Protocol (IP) addresses throughout every stage from reconnaissance to data theft.
According to Microsoft, current security tools cannot rely solely on catching isolated actions. Enterprises need to build monitoring systems capable of comprehensively analyzing the chain of user behaviors across Microsoft Cloud to nip these sophisticated intrusions in the bud.
Strengthening enterprise resilience against AI phishing traps
As demonstrated by the aforementioned campaign, the information security landscape is growing increasingly complex as hackers combine AI with human awareness vulnerabilities to optimize phishing scenarios. To thwart sophisticated attacks targeting end users, bolstering internal information security awareness is paramount.
Recognizing this, IPSIP Vietnam offers a practical Cybersecurity Training program, equipping staff with the skills to identify fraud and respond swiftly. Transform every employee into a solid shield protecting your enterprise's data systems.
Refer to: The Hacker News












Comments