Microsoft Reveals Million-Email CEO Impersonation Campaign and Passkey Phishing Attacks Targeting Business Cloud Accounts
Microsoft cybersecurity warning: CEO impersonation scams and passkey phishing attacks target businesses, using fake invoices, AI emails and cloud account abuse.
Two campaigns are targeting businesses with fake executive emails, fraudulent payment requests and passkey-themed phishing attacks designed to steal money and gain access to Microsoft cloud accounts.
Microsoft has warned about two cyberattack campaigns targeting businesses, with criminals using fake CEO emails to steal money and passkey-themed scams to gain access to cloud accounts. The attacks highlight how scammers are combining trusted services, convincing fake websites and social engineering to deceive employees.
In the first campaign, attackers sent more than one million scam emails between August 3 and 5, 2026. The messages were designed to appear as if they came from CEOs at targeted companies and were primarily aimed at finance and accounts payable teams.
The attackers claimed that the company had approved a ServiceNow annual subscription and instructed employees to make Automated Clearing House (ACH) payments to accounts controlled by the attackers.
AI Used to Make CEO Scam Emails More Convincing
Microsoft stated the attackers used generative AI to create email templates and produce messages tailored to individual recipients. The emails included fake invoices, forged approval messages and fabricated email conversations to make the payment requests appear legitimate.
The attackers also researched the names and email addresses of CEOs, CFOs and company presidents and incorporated those details into their messages.
The campaign used fake domains designed to resemble legitimate companies and services. By combining CEO impersonation, fake invoices and trusted brand names, the attackers attempted to make the emails appear more credible and reduce suspicion. Microsoft said the campaign primarily targeted enterprise organisations in the US, including businesses in IT services, consumer goods, real estate and manufacturing.
Passkey Phishing Targets Cloud Accounts
The second campaign involves passkey phishing and cloud account compromise. Microsoft said it has been tracking the activity since May 2026.
The attacks often begin with a phone call or message sent to an employee's personal number. The attacker poses as a company IT help desk representative and claims that the employee needs to update their passkey, multi-factor authentication (MFA) or single sign-on settings.
The employee is then directed to a fake Microsoft sign-in page, often through an SMS message. The attackers attempt to trick the victim into completing an adversary-in-the-middle (AitM) or device-code authentication process. If successful, this can give attackers access to a Microsoft account without requiring them to directly steal the victim's password.
Attackers Add Their Own MFA Methods
After gaining access to an account, attackers may add their own phone number, authenticator app or software-based one-time password method. This can allow them to maintain access even after the initial compromise.
Once inside, they can explore company systems and search for valuable information. Microsoft said attackers have used the Microsoft Graph API to examine users, groups, permissions and files.
They have also accessed large amounts of data stored in SharePoint, OneDrive and Exchange Online. Attackers may spend hours or even days collecting emails, attachments and company files. They can also change the IP addresses and infrastructure used during different stages of an attack, making the activity more difficult for security teams to detect.
Microsoft said the campaigns demonstrate the growing difficulty of detecting suspicious activity in cloud environments. An individual Microsoft Graph API request may appear legitimate on its own, while a sequence of seemingly normal actions can reveal a much larger attack.
For businesses, the latest Microsoft cybersecurity warning highlights the importance of carefully verifying payment requests and unexpected IT support messages. Companies should also monitor unusual login activity, newly added MFA methods, large file downloads and unexpected access to cloud services.
The campaigns also demonstrate that passkeys and MFA cannot prevent every phishing attack if users are manipulated into approving access or changing their security settings. Regular employee security training, strong identity controls and continuous account monitoring remain important parts of protecting cloud environments.
This article is based on information from The Hacker News