Microsoft Details Coordinated Campaigns Blasting Generative AI Invoice Fraud and Executing Passkey-Themed Social Engineering Attacks

In a sweeping threat intelligence disclosure, technology giant Microsoft has detailed two sophisticated and distinct cyberattack campaigns that exploit enterprise blind spots. The first operation leverages generative artificial intelligence (AI) to execute large-scale financial invoice fraud via third-party email delivery infrastructure. The second campaign deploys targeted, passkey-themed social engineering to compromise cloud environments, bypass multi-factor authentication (MFA) protocols, and harvest sensitive corporate data across global enterprises.
The findings highlight a rapidly shifting threat landscape where cybercriminal syndicates increasingly blend automated, scalable text generation with highly personalized, human-driven social engineering. According to Microsoft’s Security Research team, these operations underscore the growing convergence of commodity phishing tools and advanced, targeted persistent threats aimed directly at organizational finance and IT help desks.
AI-Powered Invoice Fraud Wave Targets Enterprise Accounts Payable
The first campaign exposed by Microsoft centers on an aggressive, automated financial fraud operation that peaked between August 3 and August 5, 2026. During this brief window, threat actors blasted upwards of one million scam emails targeting enterprise organizations primarily located in the United States. The affected sectors span a wide variety of industries, including IT services, consumer goods, real estate, and discrete manufacturing.
The mechanics of the attack represent a significant evolution from traditional, easily detectable business email compromise (BEC) attempts. Rather than relying on a solitary, disjointed social engineering hook, the attackers constructed a multi-layered narrative designed to systematically disarm the skepticism of accounts payable personnel.

The process began weeks prior to the email blast, with threat actors registering domains specifically tailored to impersonate trusted corporate entities and high-level executives. Operating under the guise of chief executive officers (CEOs), chief financial officers (CFOs), and company presidents, the scammers sent targeted payment requests through trusted, third-party email delivery infrastructure to bypass standard perimeter filters.
To add an unprecedented veneer of authenticity, the emails included fabricated vendor branding, forged internal email conversation threads discussing the transaction, and meticulously crafted invoices. The primary objective was to convince finance departments to urgently initiate Automated Clearing House (ACH) transfers to settle a supposed, recurring ServiceNow annual subscription. By embedding realistic dialogue and managerial "approvals" directly into the email body alongside signatures harvested from public professional networking platforms, the attackers drastically reduced the likelihood of internal verification.
Microsoft noted that the sheer scale, linguistic fluidity, and contextual precision of the messaging point directly to the utilization of generative AI tools. Threat actors leverage large language models (LLMs) to automatically generate convincing email templates, draft realistic follow-up conversations, and tailor phishing lures to specific corporate hierarchies without typical grammatical anomalies or awkward phrasing.
Passkey-Themed Social Engineering and Cloud Compromise
While the financial fraud campaign targeted enterprise balance sheets via automated email blasts, the second campaign documented by Microsoft focuses on targeted, identity-focused cloud intrusions. Active since at least May 2026, this campaign utilizes sophisticated voice phishing (vishing) and messaging tactics to compromise Microsoft cloud identities, subsequently granting attackers deep access to corporate resources.
The attack vector typically initiates away from corporate hardware. Threat actors contact employees directly on their personal mobile phones or via messaging applications. Posing as internal IT help desk personnel, the callers create a false sense of urgency, warning the target that their passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration must be updated immediately to prevent catastrophic access disruptions.

Unsuspecting employees are directed via SMS to fraudulent login portals hosted on malicious domains. These sites meticulously mirror authentic Microsoft sign-in interfaces. To maximize psychological manipulation, the attackers frequently employ customized URL structures, appending the victimized organization’s corporate name as a subdomain onto generic malicious root domains (e.g., ..com).
Once the user interacts with the counterfeit portal, the attackers execute adversary-in-the-middle (AitM) attacks or abuse device-code authentication flows. This methodology allows threat actors to capture active session tokens or trick the user into unknowingly authorizing access on the attacker’s behalf, effectively bypassing traditional multi-factor authentication protections without ever needing to directly brute-force the victim’s primary password.
Attribution and the Cybercrime Syndicate Nexus
Microsoft’s threat intelligence has mapped the initial access activities behind these cloud compromise campaigns to specific threat clusters, most notably Storm-3121 and Storm-3032.
Storm-3032 has been directly correlated by researchers with UNC6671—a loose-knit cybercrime collective frequently tracked under various monikers including Cordial Spider, O-UNC-045, and PREY-0058. This e-crime ecosystem is well-known within the cybersecurity community for operating public extortion brands (such as the Helix extortion brand, following a split from the BlackFile group) while concurrently utilizing shared, commoditized phishing panels, voice-phishing call centers, and initial access playbooks that are leased out or shared among disparate affiliate networks.
Analysts suggest that the overlap in infrastructure points to a commoditized cybercrime economy where specialized actors provide initial access-as-a-service (IAaaS). Once initial access is achieved, actors such as Storm-3121 hand off or pivot toward downstream extortion activities historically associated with prominent ransomware and data-theft groups like ShinyHunters.

Post-Exploitation Tactics and Persistence Mechanisms
Gaining initial entry into a corporate cloud environment marks merely the first phase of the operation. Microsoft’s investigation revealed that once threat actors secure an initial foothold, their immediate priority is transitioning a temporary breach into a durable, long-term persistent presence.
In observed incidents, actors carried out anomalous sign-ins to applications like Microsoft Office Home from unmanaged devices. From there, they leveraged high-volume Microsoft Graph API activity to systematically enumerate sensitive internal files, traverse corporate directories, and harvest data from SharePoint Online and OneDrive instances. Because Microsoft Graph API calls often blend with normal administrative traffic, isolated API requests frequently fail to trigger traditional security alerts, presenting a major detection challenge for internal security operations centers (SOCs).
Furthermore, rather than relying solely on stolen credentials or existing tokens that might expire or be revoked, the actors actively embedded themselves into the authentication lifecycle. In numerous cases, they registered an attacker-controlled secondary authentication factor—such as a new phone number, an unauthorized authenticator application, or a software-based one-time password (OTP) token—directly to the compromised user profile.
By establishing this persistent MFA foothold, the threat actors ensure they can independently sign back into the corporate ecosystem at will, even if the victim resets their primary account password, thereby maintaining continuous access for reconnaissance, email collection via REST APIs, and lateral movement.
Broader Implications and Industry Defense Strategies

The dual disclosures from Microsoft serve as a stark reminder of the evolving sophistication of modern cyber threats, highlighting how attackers are continuously adapting to security advancements like passkeys and hardware tokens by attacking the human element through advanced social engineering.
The convergence of generative AI in financial fraud campaigns lowers the technical barrier for mass-scale, highly convincing BEC operations, making traditional rule-based email filters increasingly insufficient. Simultaneously, the rise of targeted vishing and device-code manipulation demonstrates that technical security controls alone cannot protect an organization whose employees remain vulnerable to sophisticated impersonation tactics.
In response to these campaigns, Microsoft and broader industry experts emphasize that defense strategies must evolve beyond static checkpoints. Security teams are urged to implement holistic behavioral analytics that correlate cross-event API progression—particularly regarding Microsoft Graph activity—rather than analyzing individual requests in isolation.
Additionally, organizations are advised to tighten identity governance policies, strictly monitor and restrict the registration of new authentication methods, conduct mandatory employee awareness training specifically tailored around passkey and help desk vishing vectors, and adopt phishing-resistant authentication methods that cannot be easily intercepted by adversary-in-the-middle proxy infrastructures. As threat actors continue to refine their playbooks, proactive threat hunting and comprehensive cross-platform visibility remain the primary bulwarks against these persistent enterprise intrusions.







