Act
active
Passkey-themed phishing by ShinyHunters targets Microsoft 365
- Engineer — Plan: Active campaign exploiting passkey/SSO trust to bypass MFA means now is the time to enforce phishing-resistant authentication (FIDO2 hardware keys, not app-based) in M365 conditional access policies and audit OAuth app consent grants in Entra ID.
- SOC/IR — Act: Named extortion actors (ShinyHunters, Helix) are running active M365 credential theft campaigns — hunt for anomalous Entra ID sign-ins, suspicious OAuth consent grants, and new delegated permissions added to M365 tenants since this campaign surfaced.
- Leader — Plan: ShinyHunters is a data-publication extortion group; their targeting of M365 raises breach-disclosure risk for organizations holding regulated data in that platform — schedule a review of M365 data residency, DLP controls, and phishing-awareness coverage for passkey/SSO lure themes this quarter.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.