Recent revelations from Microsoft have unveiled two targeted phishing campaigns that exploit third-party email infrastructure and social engineering tactics to breach cloud environments and steal sensitive corporate data. The first campaign, which occurred over three days in August 2026, involved sending over a million scam emails that impersonated CEOs to trick accounts payable departments into authorizing fraudulent Automated Clearing House transfers for a fictitious ServiceNow subscription. The attackers used generative AI to craft convincing email templates, targeting industries such as IT services, consumer goods, real estate, and discrete manufacturing in the U.S.

These emails featured fake invoices and manipulated email threads to appear legitimate, leveraging executive impersonation and vendor branding to reduce skepticism. Attackers even inserted names and email addresses of company executives into email signatures to enhance credibility. Meanwhile, the second campaign documented by Microsoft targeted cloud accounts using identity-based social engineering. Attackers contacted employees, posing as IT support, urging them to update passkey and authentication configurations. Victims were redirected to spoofed Microsoft sign-in pages, allowing attackers to capture credentials or gain unauthorized access.

These campaigns are linked to a cybercrime group known as UNC6671. This group has been observed using credential harvesting panels and phishing infrastructure for targeted attacks. Microsoft attributes these activities to various threat actors, including Storm-3121 and Storm-3032. The attackers aim to establish persistent access by enrolling their own MFA methods, facilitating access without user involvement. By exploiting Microsoft Graph's API calls, they maintain a foothold and conduct extensive reconnaissance and data extraction. Such attacks highlight the necessity for comprehensive monitoring of API interactions and the implementation of robust security measures.