Microsoft Security Research reported cloud-account intrusions active since May 2026 in which attackers impersonate IT helpdesks through phone calls, SMS, and occasionally Microsoft Teams. The campaigns use passkey-, MFA-, and SSO-themed lures to direct users to adversary-in-the-middle phishing pages or device-code authentication flows, capturing credentials, session tokens, or attacker-authorized tokens for Microsoft cloud identities.
After gaining access, the actors register attacker-controlled MFA methods, enumerate tenant resources through Microsoft Graph, and steal data from SharePoint, OneDrive, Exchange mailboxes, and attachments. Microsoft linked the initial-access ecosystem to Storm-3121, associated with ShinyHunters and Falcon extortion activity, and Storm-3032, a BlackFile splinter operating under the Helix banner; defenders should investigate identity and cloud telemetry, revoke sessions and refresh tokens, remove unauthorized authentication methods, and require phishing-resistant MFA with restrictive Conditional Access policies.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers identified 17 FQDNs created beginning August 28, 2026, potentially linked to Com-affiliated actors including Bling Libra and CL-CRI-1116. The domains impersonate Mailchimp or SendGrid and use passkey, MFA, and SSO themes; associated subdomains suggested possible vishing targeting multiple business sectors.
Microsoft Security Research observed active intrusions targeting Microsoft cloud accounts beginning in May 2026. The activity used passkey-, MFA-, and SSO-themed helpdesk impersonation to obtain credentials, session tokens, or device-code-authorized tokens, then registered attacker-controlled MFA methods and collected cloud and email data; Microsoft linked the initial-access ecosystem to Storm-3121 and Storm-3032 among other actors.
Microsoft associated Storm-3121 with ShinyHunters and Falcon extortion activity and assessed that Storm-3032 includes BlackFile members operating under the Helix name. Microsoft also noted overlap with Google's UNC6671 activity, which Google linked to BlackFile, Helix, Falcon, Pink, and Redact extortion gangs.
Reporting detailed the campaign's use of compromised Teams accounts, attacker-controlled MFA enrollment, Microsoft Graph reconnaissance, and throttled collection from SharePoint, OneDrive, and Exchange Online. It also identified persistence telemetry, the python-httpx user agent, anonymous proxy use, and phishing domains including passkeyhelpdesk.com, secure-passkey.com, and integratedsso.com.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 35 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
15 references tracked. Mallory keeps watching after this page renders.
blog.knowbe4.com
Open sourcebleepingcomputer.com
Open sourcecysecurity.news
Open sourcecommunity.gurucul.com
Open sourcemicrosoft.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.