Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
- Passkey phishing — the "unhackable" upgrade — is now the lure. Microsoft says attackers used passkey-themed social engineering to breach cloud environments and exfiltrate data, plus a CEO-impersonation blitz pushing over a million fraud emails through third-party delivery infrastructure. We're threadbare, but not this sloppy. Who gets hurt: anyone who thinks a login prompt equals trust — corporate cloud tenants, finance teams, and execs whose "CEO" is suddenly one relay hop away from the payroll. The unsealed cargo here is convenience sold as security. What serious readers should do: check the seals — verify passkey prompts out-of-band before tapping approve; enforce phishing-resistant MFA that actually resists phishing; and stop kidding yourself that vendor boilerplate is a defense. If your data leaves the hull without a valid delivery signature, you're not the courier — you're the cargo. Delivery signature applied.