← Back to Crime & Security

Cybercrime Group Exploits Passkey Phishing to Hijack U.S. Cloud Accounts

Crime & SecurityAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

WASHINGTON — A sophisticated cybercrime collective linked to the aliases Cordial Spider, O-UNC-045, PREY-0058, and UNC6671 launched a coordinated campaign on Sept. 13, 2026, targeting United States organizations by exploiting passkey-themed phishing and CEO fraud schemes. The attackers successfully hijacked Microsoft cloud accounts to exfiltrate sensitive data and initiate unauthorized financial transfers.

The operation, detected early in the morning on Saturday, utilized deceptive login pages designed to mimic legitimate passkey authentication prompts. These fraudulent interfaces tricked users into surrendering credentials that granted the threat actors access to corporate Microsoft environments. Once inside the networks, the group executed business email compromise tactics, impersonating chief executive officers to authorize large-scale Automated Clearing House (ACH) transfers.

Security researchers identified the campaign as a dual-threat operation aimed at both immediate financial gain and long-term data monetization. The attackers prioritized high-value targets within the U.S., focusing on sectors where cloud infrastructure holds critical operational data. By bypassing traditional multi-factor authentication through passkey spoofing, the group demonstrated an evolving capability to circumvent modern security controls.

The exfiltration of data appears to be ongoing, with investigators noting that the attackers have already moved significant volumes of proprietary information to external servers. The financial component of the attack involved fraudulent wire transfers routed through compromised accounts before detection mechanisms triggered alerts. While the specific number of affected organizations remains under assessment, the scope of the intrusion suggests a widespread impact across multiple industries.

Microsoft has issued emergency advisories urging customers to review their authentication logs and revoke any suspicious access tokens immediately. The company is working with law enforcement agencies to trace the origin of the ACH transfers and secure compromised accounts. Despite these efforts, the group behind the attack remains at large, having severed connections to their command-and-control infrastructure shortly after the initial breach.

Questions remain regarding the full extent of the data stolen and whether the attackers have established persistent backdoors within the targeted networks. The use of passkey-themed lures marks a significant shift in social engineering tactics, indicating that cybercriminals are adapting quickly to new authentication standards. As financial institutions work to reverse fraudulent transfers, cybersecurity experts warn that similar campaigns could emerge in the coming days as the group refines its methods.

The incident underscores the growing sophistication of financially motivated threat actors who are increasingly targeting cloud-based identity management systems. With no confirmed attribution to a specific nation-state or criminal syndicate beyond the known aliases, the investigation continues to focus on tracing the financial trails left by the ACH transfers.

Discussion

0 / 2000