Executive Summary
Microsoft Security Research published in a report on 9 September 2026 tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs.
The activity begins with identity-focused social engineering and impersonation infrastructure, proceeds through authentication persistence and cloud reconnaissance, and is followed by targeted data access and activity consistent with data collection and potential exfiltration. Microsoft Threat Intelligence assesses that the initial access activity observed in this campaign is used by a range of threat actors, including Storm-3121, Storm-3032, and others.
Per Microsoft, defenders should investigate this sequence across identity, Microsoft Graph, SharePoint, OneDrive, and Exchange signals, then revoke sessions and remove unauthorized authentication methods for confirmed compromises.
Key Takeaways
The attack often begins with a seemingly routine call or message on a user’s personal phone number from someone claiming to be from the organization’s IT helpdesk. The passkey narrative serves as a pretext to guide victims through adversary-in-the-middle phishing or device-code authentication flows.
Following initial access, the actor’s first objective was to transform a temporary compromise into a persistent foothold. The actor enrolled an MFA method under their control, typically by registering a new phone number, authenticator application, or software-based one-time password token.
Once MFA persistence was established, the actor initiated an extensive internal reconnaissance phase using Microsoft Graph to inventory users, groups, permissions, resources, and accessible content across the tenant with the compromised identity.
Following reconnaissance, the actor transitioned into large-scale data collection across Microsoft 365 workloads using the compromised identities. Across SharePoint and OneDrive, the activity generated significant volumes of FileAccessed and FileDownloaded events, indicating systematic retrieval of cloud-hosted documents and organizational data.
Per Microsoft, organizations should enforce phishing-resistant MFA via Conditional Access. Defenders should also enforce Conditional Access that requires a managed, compliant device for Exchange, SharePoint, and Graph-privileged apps.
Indicators of Compromise
Microsoft has provided Indicators of Compromise included with this campaign, which are included below:
Indicators |
Type |
Description |
passkeyhelpdesk[.]com |
Domains |
Passkey support lure |
secure-passkey[.]com |
Domains |
Passkey security |
setupmypasskey[.]com |
Domains |
Passkey setup |
add-passkey[.]com |
Domains |
Passkey enrollment |
integratedsso[.]com |
Domains |
SSO |
oktasession[.]com |
Domains |
Identity-provider session |
keysyncos[.]com |
Domains |
Key synchronization |
oskeysync[.]com |
Domains |
Key synchronization |
oskeysetup[.]com |
Domains |
Key setup |
oskeyregister[.]com |
Domains |
Key registration |
syncmykey[.]com |
Domains |
Key synchronization |
myconnectkey[.]com |
Domains |
Key connection |
oskeyconnect[.]com |
Domains |
Key connection |
validationsetupac[.]com |
Domains |
Account validation and setup |
portalsetuphub[.]com |
Domains |
Portal setup |