Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
AIIncidentPhishing

Microsoft Discloses AI-Assisted Invoice Fraud and Passkey Phishing Campaigns

By ogwatermelon
September 14, 2026 4 Min Read
0

Microsoft has disclosed details of two active campaigns targeting enterprise cloud environments through AI-assisted executive impersonation and passkey-themed social engineering. The attacks leverage third-party email delivery infrastructure to bypass traditional defenses and have already compromised multiple organizations by tricking employees into approving fraudulent ACH transfers and surrendering their cloud identities to adversary-in-the-middle phishing pages.

What Happened: AI-Assisted Invoice Fraud and Passkey Phishing Target Microsoft 365 Users

Microsoft’s security research team detected two overlapping threat campaigns between May and August 2026. The first campaign involved sending over one million scam emails between August 3 and August 5, 2026. Furthermore, the attackers masqueraded as chief executive officers of various target companies. Their goal was to persuade accounts payable departments to initiate Automated Clearing House transfers for a supposed ServiceNow annual subscription.

Also, evidence suggests that the operators leveraged generative artificial intelligence to create email templates and draft messages tailored to each recipient. Consequently, the campaign primarily targeted enterprise users in the United States across IT services, consumer goods, real estate, and discrete manufacturing sectors.

The second campaign detected since May 2026 revolves around passkey-themed social engineering. Threat actors call or message a user’s personal phone number while claiming to be from the organization’s IT help desk. Moreover, they urge victims to update their passkey, multi-factor authentication, or single sign-on configuration to avoid access disruptions. The end goal is to guide victims through adversary-in-the-middle or device-code authentication flows and seize control of their Microsoft accounts.

Technical Details of the Attacks

The AI-assisted invoice fraud campaign follows a structured multi-stage attack chain. First, the threat actors register impersonation domains designed to look like legitimate vendor platforms. Second, they send executive-themed payment requests through trusted email infrastructure to reduce recipient skepticism. Third, the emails contain forged approval messages, fabricated invoices, and fake email threads to create a unified narrative.

In addition, the attackers identify CEOs, CFOs, and presidents at victim organizations and plug their real names and email addresses into the message signatures. Some of the registered malicious domains include:

  • service-nowinc[.]com
  • domainlify[.]net

The passkey phishing campaign uses a different but equally effective technical approach. The threat actors register domains built around passkey, SSO enrollment, account activation, and identity verification themes. Also, they include the target organization’s name as a subdomain in the pattern company-name.malicious-domain.com. Identified infrastructure includes:

  • passkeyhelpdesk[.]com
  • secure-passkey[.]com
  • setupmypasskey[.]com
  • add-passkey[.]com
  • integratedsso[.]com
  • oktasession[.]com
  • syncmykey[.]com
  • portalsetuphub[.]com

After compromise, the attackers add their own authentication methods to victim accounts. Consequently, they conduct high-volume Microsoft Graph activity, download files from SharePoint and OneDrive, and collect mailbox contents through REST APIs.

Business and Operational Impact

The financial fraud campaign sent over one million scam emails in just two days. Therefore, even a small success rate could yield significant fraudulent ACH transfers. The operational impacts include:

  • Direct financial losses from fraudulent ACH transfers approved by finance teams
  • Data exfiltration from compromised Microsoft 365 tenants including email, documents, and cloud storage
  • Identity infrastructure takeover through added attacker authentication methods
  • Reputational damage from compromised executive impersonation
  • Regulatory and compliance exposure from unauthorized data access

Also, the activity overlaps with a loose-knit cybercrime collective tracked under the monikers Cordial Spider, O-UNC-045, PREY-0058, and UNC6671. This group operates multiple public extortion brands and shares phishing infrastructure across its affiliates.

Mitigation and Recommendations

Immediate Actions for Defenders

  1. Review recent ACH transfer requests for unusual patterns or urgent executive approval themes.
  2. Audit Microsoft Entra ID sign-in logs for suspicious passkey or MFA registration events.
  3. Hunt for Microsoft Graph API activity spikes following authentication method changes.
  4. Block the identified malicious domains at the DNS and email gateway levels.

Strengthen Authentication and Verification

Organizations should implement out-of-band verification for any payment requests that arrive via email. Also, finance teams must verify payment approvals through a secondary channel such as a known phone number or in-person confirmation. Moreover, security teams should configure conditional access policies that flag or block sign-ins from unusual locations or devices after MFA method changes.

User Awareness and Training

Employees should be trained to recognize passkey-themed social engineering calls and SMS messages. In addition, IT help desks should publish clear communications stating that they will never request passkey or MFA updates via unsolicited phone calls or text messages.

Bottom line: AI-assisted phishing and passkey-themed social engineering are bypassing traditional email filters and MFA protections. Organizations must implement out-of-band verification for financial requests and closely monitor authentication method changes in their cloud identity platforms.

Incident Summary

Incident: Microsoft Discloses AI-Assisted Invoice Fraud and Passkey Phishing Campaigns
Affected Platforms: Microsoft 365, Microsoft Entra ID, Microsoft Teams
Threat Actors: Cordial Spider / O-UNC-045 / PREY-0058 / UNC6671
Disclosure Date: September 9-10, 2026
Active Period: May 2026 – August 2026
Patch Status: N/A — social engineering attack, no software vulnerability

References

  1. Microsoft Security Research, “Protecting organizations from AI-assisted executive impersonation invoice fraud,” September 10, 2026, https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/, accessed September 14, 2026.
  2. Microsoft Security Research, “Passkey-themed social engineering leads to identity and cloud compromise,” September 9, 2026, https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/, accessed September 14, 2026.
  3. The Hacker News, “Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data,” September 13, 2026, https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html, accessed September 14, 2026.

Tags:

AIIncidentPhishing
Author

ogwatermelon

Follow Me
Other Articles
Previous

UNC3569 Exploits Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

Next

CISA Confirms Active Exploitation of Critical GitLab Path Traversal

AI Botnet Breach CVE Exploit Hack Incident Infostealer Linux Mac Malware Network Phishing Ransomware RCE supply chain Vishing Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Infostealer
  • Linux
  • Mac
  • Malware
  • Phishing
  • Ransomware
  • RCE
  • supply-chain
  • Uncategorized
  • Vishing
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.