we_are_coded.by CODE · The world, decoded
БГ
Microsoft

One stolen identity, one whole cloud breached

Microsoft Security · event date: 18 May 2026Security

Microsoft disclosed Storm-2949: the attacker takes over a single user through social engineering targeting a password reset and MFA. Then the attacker drains keys, files, and databases from the entire cloud.

In short
  • Microsoft disclosed Storm-2949: an attack that starts from one identity and reaches the entire cloud (May 18).
  • The method: social engineering targeting a password reset and MFA prompt, then the attacker registers their own device.
  • What got drained: files from OneDrive/SharePoint (incl. VPN configurations) and secrets from Azure Key Vault.
Checked on30 June 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

One 'yes' on the phone. That's where the whole breach starts - the one Microsoft disclosed for the Storm-2949 group - from one compromised identity to a breach of the entire cloud: Microsoft 365, Azure, endpoint devices.

The method: the attacker starts a Self-Service Password Reset for the victim and, through social engineering (psychological manipulation, not hacking), convinces them to approve an MFA (extra login verification) prompt that looks legitimate. Then the attacker removes the existing factors and registers their own device for persistence. What got drained: files from OneDrive/SharePoint (incl. VPN configurations), secrets from Azure Key Vault (database connections, credentials), data from Storage and SQL, .pfx certificates with private keys. There is no CVE: the attacker takes over an identity through deception, not through a software flaw.

The real takeaway is different. There's no zero-day here, no brilliant exploit (a method for breaching a system). The cheapest way in is the human - one convinced 'yes' on an MFA prompt opens everything. The technology is solid. Persuasion just walks around it.

MFA isn't magic. Get someone to press 'approve' themselves, and the second factor falls. That's why defense stands on two floors - suspicion toward unexpected prompts, and a limit on how far one identity can reach if it falls anyway. The second one saves you when the first one doesn't work.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Microsoft Security - Storm-2949
Original: https://wearecoded.com/en/articles/microsoft-storm-2949.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news