Microsoft disclosed Storm-2949: the attacker takes over a single user through social engineering targeting a password reset and MFA. Then the attacker drains keys, files, and databases from the entire cloud.
- Microsoft disclosed Storm-2949: an attack that starts from one identity and reaches the entire cloud (May 18).
- The method: social engineering targeting a password reset and MFA prompt, then the attacker registers their own device.
- What got drained: files from OneDrive/SharePoint (incl. VPN configurations) and secrets from Azure Key Vault.
One 'yes' on the phone. That's where the whole breach starts - the one Microsoft disclosed for the Storm-2949 group - from one compromised identity to a breach of the entire cloud: Microsoft 365, Azure, endpoint devices.
The real takeaway is different. There's no zero-day here, no brilliant exploit (a method for breaching a system). The cheapest way in is the human - one convinced 'yes' on an MFA prompt opens everything. The technology is solid. Persuasion just walks around it.
MFA isn't magic. Get someone to press 'approve' themselves, and the second factor falls. That's why defense stands on two floors - suspicion toward unexpected prompts, and a limit on how far one identity can reach if it falls anyway. The second one saves you when the first one doesn't work.