CyberheistNews Vol 16 #38 Attackers Use Passkey-Themed Phishing to Breach Cloud Environments

KnowBe4 Team | Sep 22, 2026
Cyberheist News

CyberheistNews Vol 16 #38  |   September 22nd, 2026

Attackers Use Passkey-Themed Phishing to Breach Cloud Environments

Researchers at Microsoft are tracking a social engineering campaign that uses passkey-themed lures to trick users into granting persistent access to their accounts and online work environments.

"The attack often begins with a seemingly routine call or message on a user's personal phone number from someone claiming to be from the organization's IT helpdesk," the researchers write. "The caller creates a sense of urgency, explaining that a passkey, multifactor authentication (MFA) or single sign-on (SSO) configuration must be updated immediately to avoid disruption.

"Employees are directed to a website that closely resembles a legitimate Microsoft sign-in experience and may receive the link through SMS messages sent directly to their personal mobile phones."

The attacker's goal is to trick the victim into performing actions that will allow the attacker to intercept device codes and session tokens, rather than stealing the victim's password.

"Despite the frequent use of passkey-themed lures, passkey enrollment is often not the actor's true objective," Microsoft explains. "Instead, the passkey narrative serves as a convincing pretext to guide victims through so-called adversary-in-the-middle (AiTM) phishing or device-code authentication flows.

"In AiTM scenarios, the actor captures credentials and session tokens; in device code attacks, the victim unknowingly authorizes access on the actor's behalf. This initial interaction may leave very little forensic evidence. If the victim opens the phishing link on a personal mobile device that is not onboarded to Microsoft Defender for Endpoint, the related activity may be absent from endpoint telemetry."

The threat actors behind this activity perform extensive reconnaissance on the targeted organizations to craft highly personalized social engineering attacks. Microsoft attributes the attacks to various threat actors associated with extortion groups.

"Together, the phone-based social engineering, personalized targeting, trusted internal messaging and rapidly changing phishing infrastructure form the opening chapter of a highly coordinated intrusion designed to blend technical deception with human trust," Microsoft concludes.

More at the KnowBe4 blog with links:
https://blog.knowbe4.com/attackers-use-passkey-themed-phishing-to-breach-cloud-environments

Your Guide to Custom Security Awareness Content: The Why and How

Pairing a strong training library with content tailored to your company's policies, risks and people makes security awareness stick. Training that reflects those things, in your own leadership's voice, builds a different kind of trust.

The best part: you don't need a production background to unlock it. Create content. No studio. No video team. No timeline measured in months.

Join Martin Tschammer, Head of Security at Synthesia, and Erich Kron, CISO Advisor at KnowBe4, for a practical look at exactly how.

You'll walk away knowing:

  • What custom security content needs to cover, from real internal risk scenarios to regulatory requirements
  • How to make it short and digestible enough that people actually watch it and retain it
  • How a consistent, familiar voice and brand shape whether people follow a policy or quietly work around it
  • A simple approach to producing content without a studio, a video team or months of lead time (demo included)

Register now for the steps and tools to make your first custom video in minutes.

Date/Time: TOMORROW, Wednesday, Sept. 23, @ 2:00 PM (ET)

Save My Spot:
https://info.knowbe4.com/your-guide-to-custom-security-awareness-content?partnerref=CHN3

Warning: New Phishing Kit Targets Hundreds of Organizations

Attackers have used a new phishing platform called "BigBear 2.0" to target hundreds of organizations across more than forty countries, according to researchers at CloudSEK. In about 10% of cases, the phishing attacks were able to bypass multifactor authentication.

"The panel has exfiltrated 5,137 credential records — including 474 complete MFA-bypassed authentications," CloudSEK says. "1,032 plaintext passwords and 4,148 session cookies — affecting 3,331 unique victim IPs across 40+ countries (India, France, Saudi Arabia, New Zealand and Germany leading), with the operation still active at the time of writing.

"The multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time."

The phishing attacks proceed as follows:

  • "Step 1: Victim clicks the phishing link (typically delivered via email) and is proxied to the legitimate Microsoft login page.
  • Step 2: Victim enters email → proxy captures it and passes it to Microsoft.
  • Step 3: Victim enters password → proxy captures plaintext AND forwards to Microsoft.
  • Step 4: Victim completes MFA (TOTP, push notification, SMS) → session token issued by Microsoft is captured by the proxy.
  • Step 5: Attacker replays the captured session cookie to access the victim's mailbox, Teams, SharePoint and all connected SaaS applications — without triggering re-authentication."

While BigBear 2.0 isn't unique in this attack flow, the phishing kit stands out for its success rate. "80% of password entries resulted in session cookie capture, and the password-to-complete conversion rate exceeded 100%, indicating the AiTM relay captured session tokens even without explicit password entry in some cases," CloudSEK says.

Blog post with links:
https://blog.knowbe4.com/warning-new-phishing-kit-targets-hundreds-of-organizations

Securing Risk, Threats and AI Across Email and Teams

Attackers use generative AI to launch payload-free business email compromise (BEC) attacks against your organization. Employees may also leak sensitive data through misdirected emails, autocomplete errors and incorrect attachments. Point solutions only show you half the picture, relying on black-box AI that ignores human behavior and outbound risk.

Real protection means understanding your users' communication baselines across inbound, outbound and chat, then turning risk signals into real-time behavior change.

Join this live demo of KnowBe4's Email & Collaboration Security to see how you can leverage deep behavioral AI to catch subtle anomalies while automatically turning every inbound threat and outbound risk into an immediate, point-of-risk teachable moment.

We will showcase:

  • NEW! Defend for Google Workspace: Bringing our industry-leading API-native inbound protection, explainable AI verdicts and teachable moments directly to Gmail.
  • Contextual Outbound DLP: Intelligent misdirected content analysis and self-serve DLP rules that stop data leaks before delivery.
  • Messaging Security and Teams Posture Management: Extending defense beyond the inbox to monitor external chats, block lateral threats and harden Teams settings.
  • Point-of-Risk Coaching and Explainable AI: Real-time teachable moments and transparent verdict evidence that show end users and SOC admins exactly why a message was flagged.
  • Autonomous SOC Triage and Containment: Eliminate 50%+ of graymail noise and purge threats globally across inboxes in under two minutes.

Don't settle for security that leaves your inbound and outbound perimeter exposed. Discover how to protect the conversation wherever work happens.

Date/Time: Wednesday, Sept. 30, @ 2:00 PM (ET)

Save My Spot:
https://info.knowbe4.com/ces-demo-3?partnerref=CHN

[OPINION] AI Cybersecurity Needs Experts, Not Apocalypse Headlines

If you believe AI could soon unleash a catastrophic hacking campaign, calling the people who defend networks would seem like an obvious first step.

Yet four influential cybersecurity experts told NBC News they worry AI companies are sidelining their expertise. The report follows Anthropic CEO Dario Amodei addressing concerns that rapidly advancing models might develop the ability to hack the entire internet within a year.

After decades in cybersecurity, I have a straightforward question: What, exactly, is that feared catastrophic AI attack scenario?

The internet contains countless systems, configurations, identities and defenses. Predicting its wholesale compromise requires more than extrapolating a benchmark curve. It requires explaining the whole kill chain: entry points, exploitation, propagation and what defenders could do to interrupt the attack.

That does not make AI's offensive capabilities imaginary. It makes precision essential. Consider some of the tools already available.

1) PentestGPT uses large language models to support automated penetration testing. Research agents such as OpenHands can inspect code, execute tests and iterate on vulnerability reproduction. These systems combine models with software tools and feedback loops. Their capabilities depend on that entire setup, not simply the chatbot's name. But understanding those capabilities requires understanding the tests.

2) CyberGym evaluates vulnerability reproduction across 1,507 historical vulnerabilities in 188 software projects. In its primary setting, an agent receives a bug description and vulnerable source code. It must produce an input that triggers the flaw in the vulnerable version but not the patched version. Think of it as demonstrating that a known defective lock fails. That is valuable security work. It does not establish that the agent can burglarize an unfamiliar building.

3) ExploitGym asks a harder question: Given a vulnerability-triggering input, can the agent develop a working exploit? Its original 898 tasks span ordinary applications, Chrome's V8 engine and the Linux kernel. This moves from demonstrating a software failure toward exploiting it.

The distinction changes the scoreboard.

Chinese AI developer DeepSeek's published comparison on Hugging Face reports CyberGym scores of 88.1% for Deepseek's V4.1 Flash and 84.5% for GPT-5.6 Sol. On ExploitGym, GPT-5.6 Sol leads at 33.7%, followed by Claude Opus 5.0 at 22.1% and DeepSeek at 15.3%. Link:
https://huggingface.co/deepseek-ai/DeepSeek-V4.1-Flash

Those are vendor-reported benchmark results, not independently established probabilities of compromising your organization. Tools, time budgets, security protections and evaluation settings matter. Reproducing a crash, developing an exploit and compromising a live enterprise are different achievements.

Still, attackers do not need universal success. One exploitable system or one employee persuaded to surrender credentials can be enough.

For CHN readers, the response should be practical: accelerate patching, deploy phishing-resistant authentication, limit privileges, test recovery and train employees to verify unusual requests. Evaluate defensive AI against measurable outcomes, including how quickly it helps your team find and fix real exposure.

AI companies should bring independent vulnerability researchers, incident responders and enterprise defenders into their evaluations and safety planning. Publish the assumptions. Let practitioners challenge the scenarios. And I think it's a good idea to have frontier models test the other models for security.

We need credible warnings backed by reproducible evidence. We also need defenses that work on Monday morning. The people already fighting these attacks belong at the table.

Critical Capabilities When Evaluating Integrated Cloud Email Security

Email is still the #1 way cybercriminals get into your organization. Every day, your users face threats like credential phishing, business email compromise (BEC), ransomware and accidental data loss — all aimed directly at their inboxes. And if you're relying on traditional, gateway-based email security to stop these threats, you're leaving your organization insecure.

Modern attacks have evolved. Your defenses need to evolve, too.

This whitepaper, Critical Capabilities When Evaluating Integrated Cloud Email Security, is a must-read for IT and Security Operations (SecOps) teams looking to close email security gaps in Microsoft 365, Google Workspace and other cloud-first environments.

What's Inside:

  • Core Threat Protection Capabilities: Look beyond the basics. Get clarity on how to stop advanced threats that slip through traditional defenses — including AI-driven phishing attacks, payload-less BEC and targeted malware.
  • Outbound Security and Data Loss Prevention: It's not just about what gets in. Learn how to prevent sensitive data from leaking out, whether through misdirected emails, insider mistakes or malicious exfiltration attempts.
  • Visibility, Management and Reporting: Security without visibility is just guesswork. Find out why detailed logging, user behavior insights and centralized reporting are non-negotiable for today's SecOps teams.
  • Cloud-Native Architecture and Integrations: Legacy bolt-ons slow you down. Discover why a true cloud-native platform — one that integrates seamlessly with your existing stack — is critical for performance, scale and ease of use.

Download Now:
https://info.knowbe4.com/critical-capabilities-when-evaluating-integrated-cloud-email-security-chn


Let's stay safe out there.

Warm regards,

Stu Sjouwerman, SACP
Executive Chairman
KnowBe4, Inc.

PS: The new KnowBe4 Agent Risk Manager is worth checking out. It brings over 15 years of human risk data and expertise to the new era of the hybrid workforce
https://www.knowbe4.com/products/ai-agent-risk-manager

PPS: [GREAT NEWS] KnowBe4 Defend email security is now ready for your Google Workspace!:
https://www.knowbe4.com/products/defend

Quotes of the Week  
"Change your life today. Don't gamble on the future, act now, without delay."
- Simone de Beauvoir - Writer, Philosopher (1908-1986)

"You may delay, but Time will not."
- Benjamin Franklin - Writer, Inventor, Statesman

Thanks for reading CyberheistNews

You can read CyberheistNews online at our Blog
https://blog.knowbe4.com/cyberheistnews-vol-16-38-alert-phishing-emails-use-new-technique-to-bypass-microsoft-365-security-filters

Security News

Millions of Phishing Emails Use "ASCII Smuggling" to Bypass Security Filters

A massive phishing campaign is using invisible Unicode tag characters to evade security filters, according to researchers at Microsoft. This technique, known as "ASCII smuggling," has grown popular over the past year for launching AI prompt injection attacks, but the same tactic can hide suspicious text in emails.

"Because tag characters are invisible to humans but exist at the text-processing level, the same property that makes them useful for smuggling instructions into a model also makes them useful for obfuscating keywords before a detector evaluates them," Microsoft explains.

"The intent is inverted, but the mechanism is similar, and a user's suspicions are not raised."

In the attacks observed by Microsoft, the threat actors inserted invisible tag characters into common financial keywords such as "funding" in the phishing emails. While the message looks normal to a human, an automated scanner designed to flag suspicious keywords won't be able to read the text properly.

"To a recipient, and to parsing pipelines that drop or normalize these characters, the word still reads as 'funding,'" Microsoft writes. "To a detector matching the literal string funding, or a regex that does not account for interleaved invisible code points, the byte sequence no longer contains the contiguous keyword.

"Whether real-world detectors behave that way depends on their normalization step, which is examined below. The bigger prize for the attacker, though, is not preventing the literal string matches; it is the ML- and NLP-based models that increasingly drive modern spam and phishing classification.

"Unless a filtering system takes a picture of a message and does OCR extraction over the visual image, it may miss this type of attack."

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce workforce risk.

Microsoft has the story:
https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/

AI-Assisted Phishing Campaign Sent Over a Million Personalized Emails

Researchers at Microsoft are tracking an AI-assisted phishing campaign that sent over one million emails attempting to conduct payment diversion scams.

"The threat actor impersonated executive team members (such as a CEO, CFO, President) of multiple targeted companies, attempting to convince accounts payable departments of the same companies to process an [Automated Clearing House] payment of nearly $50,000," Microsoft says.

"More specifically, the CEOs were impersonated in multiple places in the email such as in the sender display name, reply-to display name and in the email signature. Email bodies contained a simple and direct 'approval' of the 'invoice below' as well as urged users to request a PDF version if they need it.

"Additionally, the email signature contained certain details about the spoofed CEO such as name and email address."

Additionally, the phishing emails included legitimate-looking invoices that were customized for the targeted organizations. These templates were likely crafted using generative AI, allowing the threat actors to scale the campaign with very little effort.

"To add further legitimacy, directly below the CEO signature, the actor included 'forwarded' content, specifically a professional-looking but fabricated 'ServiceNow Platform — Annual Subscription' invoice," the researchers write.

"The extremely detailed invoice contains various ServiceNow branding and logos. It has basic invoice details such as invoice number, issue and due dates, currency, amount due, payment method and itemized line items. The payment method instructed is a bank transfer to accounts controlled by the threat actor.

"Microsoft observed the use of multiple financial institutions across samples, indicating that payment destinations may vary between targets. Certain parts of the invoice are personalized to the recipient. Specifically, the 'BILLED TO' section has the recipient company name and executive name."

While these social engineering tactics aren't new, Microsoft says the phishing campaign stands out due to how it "layered executive impersonation, vendor branding, fabricated invoices and supporting email conversations into a unified narrative intended to reduce recipient skepticism."

Microsoft has the story:
https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/

What KnowBe4 Customers Say

"Greetings! I'm the Senior Systems Administrator who will be overseeing our continued rollout of KnowBe4, and I wanted to take a minute to speak about Julie C., who has been schooling us on all of the KnowBe4 features and intricacies.

"Julie has done a tremendous job educating me and my team on how KnowBe4 can be implemented, as well as on the subtleties of getting our user community informed and aware when it comes to security. We've all read the horror stories of medical organizations being disabled and held for ransom, so we have a healthy fear of having that happen to us.

"Julie's infectious personality and vast knowledge of the product have made taking on this project much more palatable to me. It's so nice to be able to work with someone who is as caring, empathetic and funny as she is. I was initially a bit apprehensive about taking on this implementation.

"I didn't want to become the annoying "Internet Police," hated by all of my users. Julie understands that I want security education to be presented in a positive way—not something that shames or humiliates users if they happen to make a mistake.

"She has been proactive and reactive for us all at once. It's not often that you find someone working with something like this who brings such genuine caring and enthusiasm to the job.

"Julie is a credit to your team and your organization. I truly appreciate everything she has done to help us with this project. Have a great day!!!"

– S.A., Senior Systems Administrator

The 10 Interesting News Items This Week
  1. Attackers now exploit 87% of vulnerabilities on or before the day they’re disclosed, up from 23% in 2020:
    https://metatrends.substack.com/p/when-both-sides-of-cybersecurity?

  2. WSJ: "How Inmates With Contraband Phones Are Scamming Families Across America":
    https://www.wsj.com/us-news/inmates-phone-scams-prisons-784f6c2c

  3. Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI:
    https://therecord.media/nsa-reorganization-five-mission-centers

  4. Sexually Explicit Deepfake Sites Target 100-Plus Politicians in Europe:
    https://www.wired.com/story/sexually-explicit-deepfake-sites-target-100-plus-politicians-in-europe/

  5. An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation:
    https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/

  6. Iranian spear-phishing attacks target dissidents, activists, and journalists:
    https://www.ncsc.gov.uk/news/uk-allies-expose-spyware-iranian-state-actors-target-dissidents-activists-journalists

  7. Chinese Hackers-for-Hire Get Professional:
    https://www.wsj.com/tech/how-a-chinese-hacking-firm-tapped-ai-to-supercharge-cyber-spying-b577c846?

  8. A surge in AI-generated phishing emails targets Australia and New Zealand:
    https://securitybrief.com.au/story/phishbyte-warns-ai-phishing-has-outpaced-detection

  9. FBI warns of scammers impersonating law enforcement:
    https://www.ic3.gov/PSA/2026/PSA260917

  10. Organized cybercriminal group refines its phishing and fraud operations:
    https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace

Cyberheist 'Fave' Links
This Week's Links We Like, Tips, Hints and Fun Stuff

Topics: Cybercrime

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, email and collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.