Microsoft has disclosed details of active cyberattack campaigns involving AI-assisted executive impersonation for financial fraud and passkey-themed social engineering designed to hijack enterprise cloud environments.
According to the Microsoft Security Research team, an August 2026 campaign utilized generative artificial intelligence to craft more than one million scam emails masquerading as company chief executive officers. The messages targeted accounts payable personnel in U.S. enterprises across IT services, real estate, consumer goods, and discrete manufacturing, urging them to initiate Automated Clearing House transfers for a fabricated ServiceNow annual subscription.
To establish credibility, the threat actors employed trusted infrastructure and registered impersonation domains such as service-nowinc.com and domainlify.net. The attack narratives layered executive impersonation, vendor branding, forged invoices, and fabricated email threads to minimize target skepticism.
A separate persistent campaign active since May 2026 focuses on cloud-based identity compromise through passkey-themed social engineering. Threat actors contact employees via phone or SMS while impersonating IT help desk personnel, directing victims to adversary-in-the-middle infrastructure and counterfeit sign-in portals carrying domains like passkeyhelpdesk.com, secure-passkey.com, and setupmypasskey.com.
Attributed in part to threat actor groups designated as Storm-3121 and Storm-3032—the latter aligning with the UNC6671 cybercrime collective—the intrusions rely on device-code authentication flows or stolen credentials. Once initial access is achieved, operators establish persistence by registering attacker-controlled multi-factor authentication methods, including new phone numbers or software-based one-time password tokens.
Microsoft noted that the adversaries subsequently execute extensive internal reconnaissance using the Microsoft Graph API, inventorying tenant resources, examining privileged roles, and performing high-volume data exfiltration across SharePoint Online, OneDrive for Business, and Exchange Online. “The attack underscores a critical detection challenge: Microsoft Graph abuse rarely appears suspicious when viewed through a single API call,” the Microsoft Security Research team stated.