CuraSec

Act active

Passkey-themed phishing by ShinyHunters targets Microsoft 365

2026-09-12 14:04 UTC · BleepingComputer · read the source ↗ #phishing#microsoft-365#social-engineering
  • Engineer — Plan: Active campaign exploiting passkey/SSO trust to bypass MFA means now is the time to enforce phishing-resistant authentication (FIDO2 hardware keys, not app-based) in M365 conditional access policies and audit OAuth app consent grants in Entra ID.
  • SOC/IR — Act: Named extortion actors (ShinyHunters, Helix) are running active M365 credential theft campaigns — hunt for anomalous Entra ID sign-ins, suspicious OAuth consent grants, and new delegated permissions added to M365 tenants since this campaign surfaced.
  • Leader — Plan: ShinyHunters is a data-publication extortion group; their targeting of M365 raises breach-disclosure risk for organizations holding regulated data in that platform — schedule a review of M365 data residency, DLP controls, and phishing-awareness coverage for passkey/SSO lure themes this quarter.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.