Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Microsoft Warns of AI-Assisted Payment Fraud and Passkey Phishing Campaigns

Microsoft Warns of AI-Assisted Payment Fraud and Passkey Phishing Campaigns

By: Jordan Vector — Cybersecurity Expert

Last updated: September 15, 2026

Human Written
Microsoft Warns of AI-Assisted Payment Fraud and Passkey Phishing Campaigns
  • Microsoft disclosed details on two cyber operations involving AI-generated executive payment scams and phone-based passkey phishing schemes targeting corporate accounts.

  • Attackers use fake IT help desk calls to bypass MFA, register rogue authentication methods for persistent access, and steal files using Microsoft Graph API scripts.

  • The attacks link to threat groups like Storm-3032 and UNC6671, highlighting the need for multi-event behavioral monitoring, out-of-band payment checks, and strict MFA auditing.

Microsoft security experts have recently flagged two separate digital attack operations that target the cloud systems of large organizations. The new attacks employ AI technologies as well as traditional methods of sending emails and advanced social engineering manipulation.

Criminals use these actions to compromise the identities of companies, illegally seize cloud-based resources, and access valuable sensitive files. Security specialists should act immediately to improve identity governance practices and keep internal systems secure.

Massive Financial Fraud Campaign Exploits Executive Impersonation and AI

The initial campaign involved sending more than one million fraudulent payment requests during a brief three-day window. Threat actors specifically targeted accounts payable departments across United States enterprise organizations. Furthermore, the attackers used generative artificial intelligence tools to draft highly tailored email templates and convincing messages.

The malicious messages masqueraded as urgent requests from chief executive officers, financial directors, and corporate presidents. Attackers gathered verified executive names and plugged them directly into stolen corporate signature blocks. Consequently, unsuspecting finance personnel received emails that appeared to come from their own internal executive leadership team.

Additionally, the emails urged finance teams to authorize immediate Automated Clearing House wire payments. The messages referenced fake annual subscription fees for legitimate enterprise software platforms like ServiceNow. To reduce victim skepticism, the actors embedded forged email threads showing fake internal management approvals.

The attackers sent the fake messages via the email infrastructure of legitimate third parties to avoid being slowed down by the normal spam filters. They also registered lookalike web domains to mirror trusted corporate entities and software vendors. Therefore, the complex layer of executive impersonation, fake invoices, and stolen branding tricked targets into transferring corporate funds.

Passkey Social Engineering Schemes Hijack Corporate Identity Infrastructure

The second operation focuses on deep cloud account intrusions using voice phishing and targeted phone messaging. Active since May 2026, this campaign manipulates employees into surrendering control of their corporate login profiles. Attackers conduct extensive research on professional networking sites to gather worker contact details and organizational hierarchy maps.

Next, threat actors call or message target employees on personal mobile phones while posing as internal help desk technicians. The callers claim that workers must immediately update their passkey settings, single sign-on links, or multi-factor authentication setups. They warn that failing to complete the update will cause sudden work access disruptions.

Phishing campaigns are also becoming more sophisticated as criminals use AI to make fraudulent messages and impersonation attempts more convincing. In a separate case, the FBI and Google disrupted an AI-powered phishing network that targeted users with deceptive attacks.

Subsequently, gullible workers receive messages with links to fake log-in websites that look like real Microsoft log-in pages. Attackers host these counterfeit portals on specialized domains built around passkey themes and security activation phrases. Furthermore, the actors attach victim-specific company names as subdomains to make the malicious links look completely legitimate.

Upon visiting the fake website, the assailants start the so-called man-in-the-middle or device-code authentication attack. With these attack strategies, the criminals can evade ordinary multi-factor authentication safeguards without using real access passwords. In some instances, compromise occurs when attackers send passkey lures through previously hijacked Microsoft Teams accounts.

Post-Exploitation Tactics and Persistent Multi-Factor Authentication Control

Once the cybercriminals obtain their first entry into the cloud account, they begin the process of creating their permanent hold on the cloud account. The criminal gang does not stop with the use of the compromised passwords but also goes ahead to register their own multi-factor authentication process.

This malicious persistence mechanism allows attackers to access victim accounts repeatedly without requiring any future user interaction. The cybercriminals will continue to log in, even if the corporate official happens to change their password. Security specialists believe that the approach allows the rogues to keep access to the targeted company without interruptions.

Subsequently, the attackers launch automated scripts using the Microsoft Graph API to map the victim organization. They inventory internal user lists, security groups, access permissions, and corporate resources across the cloud tenant. The actors also inspect high-value admin accounts to identify opportunities for internal privilege escalation.

Eventually, the operators begin high-volume data exfiltration across SharePoint Online, OneDrive for Business, and Exchange Online repositories. They extract confidential business documents, internal email folders, and file metadata over extended periods. To avoid security detection, the attackers continuously rotate their IP addresses across authentication, reconnaissance, and data extraction phases.

Strategic Industry Attribution and Identity Security Defenses

Microsoft security teams attribute the initial access activity to several threat groups, including Storm-3121 and Storm-3032. Storm-3032 overlaps with cybercrime clusters tracked as UNC6671, which broke off from earlier extortion groups. These groups usually utilize the same phishing kits, including those for voice phishing calls and overall attack infrastructure.

These incidents are difficult to detect because separate requests to Microsoft Graph API seem perfectly normal to security tools. Security operations centers must evaluate identity behavior holistically across multiple events rather than inspecting isolated API calls. Monitoring systems must flag rapid data downloads, unmanaged device logins, and sudden authentication method changes.

Organizations must train finance teams to verify all payment requests through out-of-band communication channels. Corporate security policies must state clearly that internal IT staff will never call employees demanding passkey updates. By implementing strict conditional access rules, companies can block sign-in attempts that come from untrusted devices or unknown locations.

Enterprise administrators need to regularly audit registered devices in multi-factor authentication systems to detect unauthorized add-ons. Also, the system should automatically generate alerts if the user tries to add an option from an unknown IP address. The combination of increasing employee awareness of cybersecurity issues with continuous identity monitoring is also a key aspect of preventing the emergence of cloud-related attacks.

Share this article

You might also like

Hacker Claims Data of 273,000 Aqualter Customers has been Leaked

Hacker Claims 273,000 Customer Records from French Water Firm Aqualter Leaked Online

A hacker operating under the alias ChimeraZ claims to have published a database containing contact details for 273,229 Aqualter water…

September 12, 2026
Hacker Claims 511,000 WiziShop and Dropizi Records have been Leaked

Hacker Claims 511,000 Records from French E-Commerce Platforms WiziShop and Dropizi Leaked Online

A threat actor known as ChimeraZ claims to have leaked a 127 MB JSON dataset containing 511,661 records from 21,402…

September 12, 2026
AdaptHealth Cyberattack Exposes Data of more than 4.1 Million People

US Healthcare Firm AdaptHealth Breach Exposes Health and Insurance Data of 4.1 Million People

More than 4.1 million people had their personal and medical details exposed after hackers broke into AdaptHealth’s systems. The attackers…

September 12, 2026

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.