Passkey-Themed Social Engineering Lures Attempt to Compromise Identity and Cloud Platforms

Executive Summary Microsoft Security Research published in a report  on 9 September 2026 tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs. The activity begins with identity-focused social engineering and impersonation infrastructure,…

Read More