Threats · 118 days ago
Microsoft Entra ID recovery is no longer a safety rail when attackers can turn it into account takeover. In this campaign, Storm-2949 uses self-service password reset and MFA approval prompts to seize privileged Microsoft 365 and Azure accounts, then move into high-value data and cloud infrastructure.
Microsoft says the actor targets IT staff and senior leaders, obtains Entra ID access through social engineering, then resets passwords, strips MFA, and enrolls its own Authenticator. After takeover, the group used Microsoft Graph, OneDrive, SharePoint, and Azure resources to enumerate identities and pull large volumes of sensitive files.
The practical shift is that recovery workflows now sit on the attack path. If an attacker can persuade a user to approve reset prompts, the usual trust placed in MFA does not hold, and the compromise can extend from one privileged identity into broader Microsoft 365 and Azure exposure.
1 source covering this story
Microsoft Self-Service Password Reset abused in Azure data theft attacks
A threat actor targeting Microsoft 365 and Azure production environments is stealing data in attacks that abuse legitimate applications and administration features.
Part of the PlainSec briefing for 2026-05-19