The record
Written from the 1 report below. Nothing here is unsourced.
- Microsoft has disclosed two fraud and hacking campaigns targeting companies that use its cloud services.
- In the first campaign, attackers sent over a million fake emails between August 3 and 5, 2026, posing as company CEOs and using fake invoices to trick finance departments into making bank transfers.
- The attackers appear to have used generative AI to write the scam emails and registered fake domains to impersonate trusted brands and executives.
- In the second campaign, attackers phoned employees claiming to be from the IT help desk and directed them to fake Microsoft sign-in pages to steal credentials or account access, then downloaded data from SharePoint, OneDrive, and mailboxes.
- The schemes matter because they can drain company funds through fraudulent payments and expose sensitive corporate data stored in cloud accounts.
What to watch next
- Whether Microsoft or other providers publish further technical indicators or takedowns of the impersonation domains listed in the report.
- Whether the reported links between the cloud intrusion activity and groups such as UNC6671, Storm-3121, and Storm-3032 are confirmed.
- Whether the report's truncated final case detail — involving at least one investigated incident — is clarified in a follow-up disclosure.
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Microsoft Security Research team
1 quote · 1 outlet
“The campaign follows steps before and during the execution of the campaign: threat actors register impersonation domains, send executive-themed payment requests through trusted infrastructure, embed fabricated invoices and supporting conversations, and attempt to convince finance personnel to initiate ACH transfers”
In the article
…of email templates and draft emails tailored to their recipients. The activity primarily singled out enterprise users in the U.S., spanning IT services, consumer goods, real estate, and discrete manufacturing sectors. " The campaign follows steps before and during the execution of the campaign: threat actors register impersonation domains, send executive-themed payment requests through trusted infrastructure, embed fabricated invoices and supporting conversations, and attempt to convince finance personnel to initiate ACH transfers ," the Microsoft Security Research team said. "Unlike traditional invoice scams that rely on a single social engineering lure, this campaign layered executive impersonation, vendor branding, fabricated invoices, and…
Microsoft
tech giant
1 quote · 1 outlet
“The attack underscores a critical detection challenge: Microsoft Graph abuse rarely appears suspicious when viewed through a single API call”
In the article
…user. - Deliberately rotate infrastructure across the attack lifecycle and use separate IP addresses for authentication, reconnaissance, and exfiltration activities so as to subvert network-based indicators. " The attack underscores a critical detection challenge: Microsoft Graph abuse rarely appears suspicious when viewed through a single API call ," Microsoft said. "This attack serves as a strong example of why Graph activity must be assessed holistically, with emphasis on behavioral progression and cross-event correlation rather than individual API requests in…
Coverage1
All filed from India
Named United States · Cordial Spider · Helix · Mandiant · Microsoft · ShinyHunters · Storm-3032 · Storm-3121 · UNC6671
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
