Microsoft reports AI invoice scams and passkey phishing targeting cloud accounts
Microsoft has disclosed two active campaigns targeting business accounts, according to The Hacker News. One uses AI to create fake invoices that trick finance staff into sending money. The other uses fake IT help desk calls to steal cloud login details. Both methods allow attackers to access sensitive company data or steal funds.
Microsoft has disclosed two active campaigns targeting business accounts, according to The Hacker News. One uses AI to create fake invoices that trick finance staff into sending money. The other uses fake IT help desk calls to steal cloud login details. Both methods allow attackers to access sensitive company data or steal funds.
The first campaign ran between August 3 and 5, 2026. Attackers sent over a million scam emails pretending to be CEOs. They wanted accounts payable staff to make fake ACH transfers for a supposed ServiceNow subscription. Microsoft said the operators used generative AI to tailor the emails. They even forged email threads and invoices to make the request look legitimate.
A second campaign, detected since May 2026, uses fake calls or texts claiming to be from the IT help desk. The attackers urge users to update their passkey or multi-factor authentication to avoid access disruptions. Microsoft reported these fake IT requests redirect users to counterfeit websites that mimic Microsoft sign-in pages. The goal is to steal credentials or bypass security safeguards.
Once inside, attackers register their own authentication methods to maintain access. They then download files from SharePoint and OneDrive. Microsoft attributed the initial access activity to threat actors Storm-3121 and Storm-3032. The latter is linked to the UNC6671 collective and the Helix extortion brand.
What to check this week
If you run a small office, here’s what to do. Check with your finance team to see if they received any unexpected payment requests for software subscriptions like ServiceNow. Verify any urgent requests to update passkeys or multi-factor authentication by contacting your IT provider directly. Don’t use links in emails or texts.
The invoice scam is clever. It layers executive impersonation, vendor branding, and fabricated invoices into a unified narrative. It’s designed to reduce recipient skepticism. The passkey scam is equally tricky. It uses voice phishing to guide you through a fake sign-in flow. Ask whoever runs your IT whether this is already handled. It probably is.
Sources: The Hacker News, thehackernews.com.
30th West Technology Solutions
IT support for Antelope Valley businesses
When you call, you talk to an owner — not a call center.
Veteran-owned · Rosamond · English & Spanish