Data breaches

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Published September 11, 2026 · Bleeping Computer

Microsoft has warned that extortion-focused groups, including those tied to ShinyHunters and Helix, are running social engineering campaigns that pose as passkey and single sign-on prompts. The goal is to take over corporate Microsoft accounts and extract data stored in Microsoft 365 services, which is then typically used for extortion.

Read the full story at Bleeping Computer

More on data breaches

This is a short, independently-written summary -- not a copy of the original reporting. Always read the full story at the source link above.