TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

Hackers Abuse Microsoft Password Reset to Steal Data

Akinola Ajibola by Akinola Ajibola
May 21, 2026
in Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • Data is being stolen by a threat actor who is targeting Microsoft 365 and Azure production installations using assaults that misuse administrator features and valid applications.
  • The attack’s goal, according to Microsoft, is “to exfiltrate as much sensitive data from a target organization’s high-value assets as possible.” The actor is identified as...
  • In order to access data in Microsoft 365 applications, Storm-2949 employed social engineering to target users with privileged responsibilities, such as IT staff or senior leadership,...

Data is being stolen by a threat actor who is targeting Microsoft 365 and Azure production installations using assaults that misuse administrator features and valid applications.

The attack’s goal, according to Microsoft, is “to exfiltrate as much sensitive data from a target organization’s high-value assets as possible.” The actor is identified as Storm-2949.

In order to access data in Microsoft 365 applications, Storm-2949 employed social engineering to target users with privileged responsibilities, such as IT staff or senior leadership, and obtain their Microsoft Entra ID credentials.

According to Microsoft, the Self-Service Password Reset (SSPR) flow, in which an attacker starts a password reset for a targeted employee’s account and subsequently deceives the victim into accepting multi-factor authentication (MFA) prompts, is allegedly misused by the actor.

The hacker pretends to be an IT support worker who needs the account to be verified immediately in order to make the hoax seem more plausible.

After that, the hacker enabled Microsoft Authenticator on their device, changed the password, and disabled the MFA controls.

Using the Microsoft Graph API and custom Python scripts, Storm-2949 targeted Microsoft 365 apps, enumerated people, roles, applications, and service principals, and assessed the long-term persistence prospects in each scenario.

They then used Microsoft 365’s OneDrive and SharePoint to check for VPN settings and IT operational files in order to find remote access information that would be useful for lateral movement from the cloud into the endpoint network.

Microsoft says that “Storm-2949 downloaded thousands of files to their own infrastructure in a single action using the OneDrive web interface.”

“All compromised user accounts exhibited this pattern of data theft, probably as a result of different identities having access to different shared directories and folders.”

The victim’s Azure infrastructure, including virtual machines, storage accounts, key vaults, app services, and SQL databases, was also targeted by Storm-2949.

Switching to Azure: Microsoft claims that the attacker gained access to several identities with privileged bespoke Azure role-based access control (RBAC) roles on several Azure subscriptions.

They were able to “uncover and extract the most sensitive assets within the victim’s Azure environment, specifically from production-based Azure subscriptions.”

Storm-2949 obtained credentials to install FTP, Web install, and the Kudu console for administering Azure App services by taking advantage of the compromised user’s privileged Azure RBAC rights.

Also worth reading
Microsoft Puts Apps And Always-On Agents Inside Copilot Microsoft Rebuilds Defender Security Operations For AI Agents OpenAI And Microsoft Feared AI Could Break The Web Microsoft’s Patch Tuesday Shows AI Is Finding Bugs Fast Microsoft 365 Outage Shows Cloud Dependence Has A Cost Microsoft And ILO Take Digital Skills Training To Kenya’s Refugee Youth

The actor could now examine environment variables, traverse the file system, and remotely carry out operations within the context of the application.

After that, Storm-2949 switched to Azure Key Vaults, where they stole numerous secrets, including connection strings and database credentials, and altered access settings.

By altering firewall and network access rules, obtaining storage keys and SAS tokens, and exfiltrating data using bespoke Python scripts, the attackers also targeted Azure SQL servers and storage accounts.

Additionally, according to Ganacharya, the Storm-2949 malicious activity is unrelated to the recent Microsoft Entra SSO and device code phishing threats [1, 2, 3].

Microsoft advises adhering to security hardening and best practices, such as implementing the least privilege principle, enabling conditional access policies, adding MFA protection for all users, and guaranteeing phishing-resistant MFA for users with privileged roles, such as administrators, in order to fend off Storm-2949 attacks.

The company recommends limiting Azure RBAC permissions, limiting access to Key Vault, limiting public access to Key Vaults, employing data protection options in Azure Storage, monitoring for high-risk Azure management operations, and retaining Azure Key Vault logs up to a year in order to secure cloud resources. 

In addition to comprehensive mitigation and prevention guidelines, Microsoft’s whitepaper offers indicators of compromise for the reported threats. 

To protect enterprise environments from these SSPR-based social engineering attacks, security teams should consider implementing several key architectural defenses.

Firstly, organisations should enforce phishing-resistant multi-factor authentication. This means upgrading high-risk, privileged, and administrative roles to use stronger mechanisms such as FIDO2 security keys or certificate-based authentication.

Secondly, security teams need to tighten SSPR requirements. Specifically, they should adjust Entra ID policies to require two verification methods for self-service password resets instead of relying on just a single prompt or an SMS factor as an alternative.

Third, companies should adopt a strict least-privilege RBAC model. By severely limiting Azure Role-Based Access Control permissions, organizations can ensure that a compromised account cannot easily access secondary high-value storage accounts or key vaults.

Finally, teams must prioritize audit and log retention. This involves retaining Azure Key Vault logs for up to one full year while continuously monitoring for high-risk management operations or any anomalous data access patterns.

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • microsoft-authenticator_fhch
    Critical Vulnerability In Microsoft Authenticator…
  • Announcing-the-new-admin-center-1c
    Microsoft 365 Admin Center Logins Will Require MFA
  • csm_1200x630wa_5026e9630c
    Microsoft Pushes Edge & Disables Authenticator Autofill
  • 1756485691039
    Microsoft to Enforce MFA on Azure Resource…
  • Chinaflag_computercode_MykhailoPolenok-AlamyStockPhoto
    New Malware Deployed By Chinese APT To Retain Access…
  • Microsoft Teams
    Microsoft Teams Vulnerability Exposes User Systems
  • Nigeria-Police-oje751ajvij3f7dy7z0qk7rmbhejx6zy56z3i8uxdc
    Nigerian Authorities Arrest Developer Linked to…
  • skynews-russia-hacker_5812455
    Russian Hackers Target WhatsApp for Data on Ukraine
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: azurehackersmicrosoftmicrosoft 365password
Akinola Ajibola

Akinola Ajibola

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • ASOS Warns Customer Details May Have Been Accessed After App Alert October 7, 2026
  • Milsat Is The Nigerian Startup Behind The New Digital Postcode October 7, 2026
  • Airtel Money IPO Leaves Nigeria SmartCash Outside The Listing October 7, 2026
  • Multiply Labs Raises $75M To Bring Robots Into Drug Manufacturing October 7, 2026
  • Wikimedia Says OpenAI Agents Made Unauthorized Wiki Edits October 7, 2026
  • Google Bets On Existing Nuclear Plants To Power Its AI Growth October 7, 2026
  • Google Nano Banana 2.1 Brings Cheaper AI Images To Gemini October 7, 2026
  • Boston Dynamics Names Alexa Veteran Rohit Prasad CEO October 7, 2026
  • OpenAI Opens AI-Generated Math Results To Public Scrutiny October 7, 2026
  • Transsion Opens Hong Kong Share Sale As Africa Phone Giant Seeks $428M October 7, 2026
  • Mistral Large 4 Puts A 1-Trillion-Parameter Model In Public Preview October 6, 2026
  • Vinci Raises $250 Million To Speed Up Chip Design With AI October 6, 2026

Browse Archives

October 2026
M T W T F S S
 1234
567891011
12131415161718
19202122232425
262728293031  
« Sep    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.