I spent a significant portion of my early career as a penetration tester trying to trick employees into clicking malicious links. Back then, it was easy. A poorly formatted email with a few spelling errors and a suspicious attachment usually did the trick. Today, the game is entirely different. I recently analyzed a series of campaign logs from a massive August breach, and the level of polish is unsettling. The attackers no longer rely on your inability to spot a typo. They rely on your desire to be secure and your trust in legitimate corporate processes.
Between August 3 and 5, 2026, Microsoft tracked a sophisticated threat actor that sent over one million scam emails. These messages targeted accounts payable departments in the United States across several sectors, including real estate and manufacturing. The goal was simple: convince finance personnel to initiate Automated Clearing House transfers for a fake ServiceNow subscription. What makes this incident a masterclass in modern social engineering is how the attackers leveraged the industry-wide shift toward passkeys to bypass traditional defenses.
Phishing has historically suffered from the uncanny valley problem. A message would look almost right, but the tone would feel off. This campaign removed that friction. Microsoft Security Research found evidence that the operators used generative artificial intelligence to draft email templates. By feeding the AI actual corporate communications or executive bios, the attackers generated text that mimicked the specific professional voice of a target CEO. This is the digital Trojan horse of the AI era. It is no longer a generic lure; it is a tailored narrative.
When a finance officer receives an email that sounds exactly like their boss, their skepticism drops. The attackers did not just send a single invoice. They layered the attack with fabricated email threads. These threads made it appear as though the CEO and other executives had already discussed and approved the ServiceNow payment. From a risk perspective, this creates a false sense of institutional consensus. The employee is not just paying a bill. They are executing a directive that appears to have moved through the proper chain of command.
Behind the scenes, the attackers abused third-party email delivery infrastructure to send these messages. This is a clever way to evade security gateways. Because the emails originate from trusted, high-reputation servers, they often bypass the initial spam filters that would catch a newly registered domain. The infrastructure is legitimate, but the content is malicious.
Passkeys are supposed to be the end of phishing. By using FIDO2 standards, they tie a user's identity to a physical device and a specific domain. This prevents a user from accidentally entering their credentials into a fake site. However, the transition period between legacy passwords and modern passkeys is a massive attack surface. The Microsoft report highlights how threat actors now use passkey-themed social engineering to breach cloud environments.
In many cases, the lure involves a message that tells the user their account security is out of date. The email prompts the user to "upgrade" to a passkey to meet new corporate security requirements. This is the architectural paradox of modern security: the more we tell users to adopt new tech, the more they expect to see prompts about it. When the user clicks the link, they are directed to an Adversary-in-the-Middle (AitM) proxy.
This proxy sits between the user and the real Microsoft login page. As the user attempts to "set up" their passkey, the attacker captures the session token in real-time. This token is a golden ticket. It allows the attacker to bypass Multi-Factor Authentication (MFA) because the system believes the user has already authenticated. The attacker is not cracking the passkey; they are hijacking the enrollment process itself.
Once the attacker gains access to the cloud environment via a hijacked session, the mission shifts to persistence and exfiltration. In the August campaign, the goal was financial fraud, but the access allowed for much more. Once inside a Microsoft 365 environment, an attacker has a granular view of the company's internal workings. They can read sensitive contracts, view payroll data, and monitor internal chats to find their next target.
From an end-user perspective, nothing seems wrong. There is no alert for a new login because the attacker used a valid session token. This is where the concept of the network perimeter as an obsolete castle moat becomes clear. The attacker is already inside the vault because they stole the guard's badge while it was being issued.
Data integrity is the next casualty. Attackers can modify bank account details on saved invoice templates or set up mail forwarding rules that hide their tracks. If an accounts payable clerk replies to a suspicious email to verify it, a hidden rule might instantly move that reply to the trash. The clerk thinks they are being ignored, while the attacker continues to pull the strings from a compromised mailbox.
We often talk about the human firewall, but even the best firewall fails if the underlying protocol is flawed. Relying on employees to spot AI-generated impersonation is a losing strategy. As a countermeasure, organizations must move toward strict phishing-resistant MFA. This means moving away from SMS codes and push notifications toward hardware keys or platform-bound passkeys that do not allow for easy AitM hijacking.
However, technology is only half the battle. Proactively speaking, the finance department needs a verification process that exists outside of email. If a CEO asks for a million-dollar ACH transfer, the policy should require a secondary verification via a known phone number or a face-to-face video call. These out-of-band checks are the only way to break the narrative that AI builds so well.
Assessing the attack surface also requires looking at third-party risks. The attackers in this campaign impersonated ServiceNow, a pervasive vendor in the IT space. If your organization uses these services, your employees are pre-conditioned to trust emails with that branding. This makes the impersonation much more effective.
Security is not a final state. It is a continuous process of hardening. To defend against these AI-driven campaigns, IT teams should implement Conditional Access policies that are as stringent as possible. For example, you can restrict session token lifetimes or require that logins only occur from compliant, company-managed devices. This limits the utility of a stolen session token.
Looking at the threat landscape, it is clear that attackers are no longer just looking for technical vulnerabilities in software. They are looking for vulnerabilities in our workflows. They exploit the fact that we are busy, that we want to be helpful, and that we trust the tools our companies provide.
I always tell my sources that the most dangerous exploit is the one that looks like a standard operating procedure. This August campaign proved that a mix of GenAI and identity-themed lures can bypass even high-end security stacks. Patching aside, the most mission-critical defense you have is a culture where "trust but verify" is not just a slogan, but a mandatory part of every financial transaction.
Sources:
Disclaimer: This article is for informational and educational purposes only. It does not replace a professional cybersecurity audit or incident response service. Always consult with a qualified security professional before making changes to your organization's security posture.



Our end-to-end encrypted email and cloud storage solution provides the most powerful means of secure data exchange, ensuring the safety and privacy of your data.
/ Create a free account