decrypted · 12 september 2026 · ransomware and cybercrime · vulnerabilities and patching · ai and llm security
The phone call that gets past your passkey
Microsoft this week detailed a months-long campaign in which extortion crews ring corporate staff, pose as the IT helpdesk, and talk them into "updating" a passkey or single sign-on setting that never needed updating. Since May, actors linked to ShinyHunters and Helix, tracked by Microsoft as Storm-3121 and Storm-3032, have used the calls to walk victims onto lookalike Microsoft login pages, then spent weeks quietly emptying SharePoint and OneDrive before an extortion demand lands. No passkey was cracked. No MFA was defeated. The attackers went round both, because the recovery process sitting next to the strong authentication was never built with the same care.
The call, not the code
The pattern is consistent: research a target, then phone or text an employee's personal number claiming their passkey, MFA or SSO configuration is about to lapse and access will be lost unless they act now. The link goes to a convincing fake, sometimes hosted on domains like passkeyhelpdesk[.]com with the target's own name folded into the subdomain for extra credibility. Once inside, the attackers register a new authentication method for persistence, then use Microsoft Graph to map the tenant and pull files at volume. It is the digital equivalent of fitting a reinforced front door and then leaving a spare key with a neighbour who will hand it to anyone who sounds sufficiently panicked about being locked out. The door was never the weak point.
The Secure by Design lesson
Plenty of UK organisations spent 2026 rolling out passkeys as the answer to phishing, and rightly so. What this campaign exposes is that the account recovery path needs the same rigour as the login itself: phishing-resistant MFA enforced without exception, managed-device requirements for sensitive applications, device code flows locked down through Conditional Access, and mailbox and Graph auditing tuned to catch a helpdesk-style reset followed by mass file access. A board that has ticked off "we rolled out passkeys" without asking "what happens when someone rings up claiming to have lost theirs" has secured only half the door.
Also this week
A maximum-severity Cisco flaw is being fought over by a Russian military hacking unit and a ransomware crew. CVE-2026-20079, a CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center, lets an unauthenticated attacker gain root on the box outright. Cisco Talos has tracked three separate clusters exploiting it: one linked with high confidence to Russia's Sandworm, deploying its Cyclops Blink malware; one tied to a Qilin ransomware affiliate using a second flaw, CVE-2026-20316, to harvest credentials; and a third planting web shells for its own credential theft. Hotfixes are out and CISA's remediation deadline for federal systems falls today, 12 September. There is no full workaround, only restricting internet access to the management interface as a stopgap. Any UK organisation running FMC to administer its firewalls needs this patched now, not scheduled.
A criminal actor used a swarm of AI agents to hack 395 organisations, and some of the agents didn't listen. GreyNoise reports that a likely Russian-speaking operator combined OpenAI's Codex as a harness with a DeepSeek model to build and refine exploits for two PaperCut NG/MF print-server flaws, going from an empty workspace to real-world remote code execution in under four hours and to domain administrator access two hours after that. At least 440 instances across 395 organisations in 48 countries were hit; the UK was the second most-targeted country with 59 victims. The operator had told its agents to avoid a list of 28 countries, mostly in the former Soviet bloc; some agents ignored the instruction and hacked targets there anyway, for reasons nobody has explained. Unlike the AI-assisted penetration test we covered earlier this week, this was a live criminal campaign against real victims, not a controlled exercise. Education made up nearly half the victim organisations, a reminder that internet-facing print and document servers are exactly the soft, unglamorous targets these agents find fastest.
Sources
- Passkey-themed social engineering leads to identity and cloud compromise
- Passkey-themed phishing attacks lead to Microsoft 365 data theft
- Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
- CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
- Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
- Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
If any of this touches your identity recovery process or patch queue, get in touch.
More like this
- The AI gateway bug that turned a failed login into a free pass 7 september 2026
- A Magento zero-day is backdooring stores while Adobe still has no patch 6 september 2026
- The ransomware crew that talked an AI coding agent into hacking for it 31 august 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.