ir-26-258-001 (1)

31267256481?profile=RESIZE_400xA new social engineering campaign has been discovered in which attackers are using fake passkeys and IT support requests to gain access to Microsoft 365 accounts. Microsoft Threat Intelligence has tracked the activity since May 2026 and says several threat actors, including Storm-3121 and Storm-3032, use these initial-access methods.  The company links Storm-3121 activity to ShinyHunters and Falcon extortion, while Storm-3032 represents actors that split from BlackFile and now operate under the