TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

Hackers Abuse Microsoft Password Reset to Steal Data

Akinola Ajibola by Akinola Ajibola
May 21, 2026
in Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • Data is being stolen by a threat actor who is targeting Microsoft 365 and Azure production installations using assaults that misuse administrator features and valid applications.
  • The attack’s goal, according to Microsoft, is “to exfiltrate as much sensitive data from a target organization’s high-value assets as possible.” The actor is identified as...
  • In order to access data in Microsoft 365 applications, Storm-2949 employed social engineering to target users with privileged responsibilities, such as IT staff or senior leadership,...

Data is being stolen by a threat actor who is targeting Microsoft 365 and Azure production installations using assaults that misuse administrator features and valid applications.

The attack’s goal, according to Microsoft, is “to exfiltrate as much sensitive data from a target organization’s high-value assets as possible.” The actor is identified as Storm-2949.

In order to access data in Microsoft 365 applications, Storm-2949 employed social engineering to target users with privileged responsibilities, such as IT staff or senior leadership, and obtain their Microsoft Entra ID credentials.

According to Microsoft, the Self-Service Password Reset (SSPR) flow, in which an attacker starts a password reset for a targeted employee’s account and subsequently deceives the victim into accepting multi-factor authentication (MFA) prompts, is allegedly misused by the actor.

The hacker pretends to be an IT support worker who needs the account to be verified immediately in order to make the hoax seem more plausible.

After that, the hacker enabled Microsoft Authenticator on their device, changed the password, and disabled the MFA controls.

Using the Microsoft Graph API and custom Python scripts, Storm-2949 targeted Microsoft 365 apps, enumerated people, roles, applications, and service principals, and assessed the long-term persistence prospects in each scenario.

They then used Microsoft 365’s OneDrive and SharePoint to check for VPN settings and IT operational files in order to find remote access information that would be useful for lateral movement from the cloud into the endpoint network.

Microsoft says that “Storm-2949 downloaded thousands of files to their own infrastructure in a single action using the OneDrive web interface.”

“All compromised user accounts exhibited this pattern of data theft, probably as a result of different identities having access to different shared directories and folders.”

The victim’s Azure infrastructure, including virtual machines, storage accounts, key vaults, app services, and SQL databases, was also targeted by Storm-2949.

Switching to Azure: Microsoft claims that the attacker gained access to several identities with privileged bespoke Azure role-based access control (RBAC) roles on several Azure subscriptions.

They were able to “uncover and extract the most sensitive assets within the victim’s Azure environment, specifically from production-based Azure subscriptions.”

Storm-2949 obtained credentials to install FTP, Web install, and the Kudu console for administering Azure App services by taking advantage of the compromised user’s privileged Azure RBAC rights.

Also worth reading
Microsoft And ILO Take Digital Skills Training To Kenya’s Refugee Youth Microsoft’s AI Buildout Runs Into The Hard Math Of Chips And Power Microsoft’s China Retreat Redraws Big Tech’s AI Map Microsoft’s Copilot Cleanup Shows AI Super Apps Still Need Focus Inforcer Raises $50M As AI Turns Microsoft 365 Security Into An MSP Problem Microsoft Cloud Growth Jumps As Azure Gives AI Spending A Better Answer

The actor could now examine environment variables, traverse the file system, and remotely carry out operations within the context of the application.

After that, Storm-2949 switched to Azure Key Vaults, where they stole numerous secrets, including connection strings and database credentials, and altered access settings.

By altering firewall and network access rules, obtaining storage keys and SAS tokens, and exfiltrating data using bespoke Python scripts, the attackers also targeted Azure SQL servers and storage accounts.

Additionally, according to Ganacharya, the Storm-2949 malicious activity is unrelated to the recent Microsoft Entra SSO and device code phishing threats [1, 2, 3].

Microsoft advises adhering to security hardening and best practices, such as implementing the least privilege principle, enabling conditional access policies, adding MFA protection for all users, and guaranteeing phishing-resistant MFA for users with privileged roles, such as administrators, in order to fend off Storm-2949 attacks.

The company recommends limiting Azure RBAC permissions, limiting access to Key Vault, limiting public access to Key Vaults, employing data protection options in Azure Storage, monitoring for high-risk Azure management operations, and retaining Azure Key Vault logs up to a year in order to secure cloud resources. 

In addition to comprehensive mitigation and prevention guidelines, Microsoft’s whitepaper offers indicators of compromise for the reported threats. 

To protect enterprise environments from these SSPR-based social engineering attacks, security teams should consider implementing several key architectural defenses.

Firstly, organisations should enforce phishing-resistant multi-factor authentication. This means upgrading high-risk, privileged, and administrative roles to use stronger mechanisms such as FIDO2 security keys or certificate-based authentication.

Secondly, security teams need to tighten SSPR requirements. Specifically, they should adjust Entra ID policies to require two verification methods for self-service password resets instead of relying on just a single prompt or an SMS factor as an alternative.

Third, companies should adopt a strict least-privilege RBAC model. By severely limiting Azure Role-Based Access Control permissions, organizations can ensure that a compromised account cannot easily access secondary high-value storage accounts or key vaults.

Finally, teams must prioritize audit and log retention. This involves retaining Azure Key Vault logs for up to one full year while continuously monitoring for high-risk management operations or any anomalous data access patterns.

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • microsoft-authenticator_fhch
    Critical Vulnerability In Microsoft Authenticator…
  • Announcing-the-new-admin-center-1c
    Microsoft 365 Admin Center Logins Will Require MFA
  • csm_1200x630wa_5026e9630c
    Microsoft Pushes Edge & Disables Authenticator Autofill
  • 1756485691039
    Microsoft to Enforce MFA on Azure Resource…
  • Chinaflag_computercode_MykhailoPolenok-AlamyStockPhoto
    New Malware Deployed By Chinese APT To Retain Access…
  • Microsoft Teams
    Microsoft Teams Vulnerability Exposes User Systems
  • skynews-russia-hacker_5812455
    Russian Hackers Target WhatsApp for Data on Ukraine
  • Nigeria-Police-oje751ajvij3f7dy7z0qk7rmbhejx6zy56z3i8uxdc
    Nigerian Authorities Arrest Developer Linked to…
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: azurehackersmicrosoftmicrosoft 365password
Akinola Ajibola

Akinola Ajibola

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Rivian Spinout ALSO Turns E-Bikes Into An Autonomous Delivery Bet August 23, 2026
  • Apple’s Foldable iPhone May Be Real, But The Trade-Offs Are Too August 23, 2026
  • Apple Job Cuts Point To A New Siri And Vision Pro Reset August 22, 2026
  • TikTok’s $400M Privacy Settlement Shows Child Safety Costs Are Rising August 22, 2026
  • OpenAI Cuts GPT-5.6 Sol API Prices As AI Price War Deepens August 22, 2026
  • Apollo Data Breach Shows Wall Street’s Cloud Security Problem August 21, 2026
  • Tesla’s China Recall Turns Hidden Door Handles Into A Safety Issue August 21, 2026
  • Oura Lawsuit Puts AI Sleep Tracking Under Legal Pressure August 21, 2026
  • Ericsson And MTN Move MoMo Onto Cloud Across Four Markets August 21, 2026
  • Kenya’s Digital ID Talks Put Trust Back At The Centre August 21, 2026
  • Starcloud’s $250M Raise Pushes Orbital AI Data Centres Closer August 21, 2026
  • Micron’s $10B Boise Lab Makes Memory A Bigger AI Battleground August 21, 2026

Browse Archives

August 2026
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
31  
« Jul    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.