Skip to content Skip to sidebar Skip to footer

Passkeys Become a Phishing Lure? Hackers Target Microsoft 365 Accounts in New Attack

Hackers using passkeys as a phishing lure to target Microsoft 365 accounts

Passkeys are widely promoted as a safer alternative to traditional passwords. But attackers have found another way to exploit the technology: using the passkey concept itself as a phishing lure.

Microsoft has disclosed cloud attacks in which threat actors impersonate corporate IT help desks and contact employees through phone calls or messages. Victims are told that they need to update their passkey, MFA, or SSO configuration to avoid losing access to company services.

The real objective is very different.

Victims are redirected to phishing infrastructure or authentication flows that can ultimately give attackers access to their Microsoft accounts.

Passkeys Are Not Being Cracked

This distinction is important.

The campaign does not mean that attackers have simply broken the cryptography behind passkeys. Instead, they are exploiting human trust in modern authentication systems.

The victim receives what appears to be a legitimate security request. The attacker may claim that a passkey needs to be updated, MFA needs to be reconfigured, or SSO access needs to be restored.

Because these terms are strongly associated with account security, the request can sound completely legitimate.

The problem starts when the victim follows the attacker's instructions.

The Attack Can Start With a Fake IT Help Desk Call

Microsoft observed attack patterns in which threat actors contacted employees through their personal phone numbers while pretending to be members of the organization's IT help desk.

The attacker then creates urgency.

The employee may be told that their passkey, MFA, or SSO configuration needs immediate attention or their access could be interrupted.

A link may then be sent through SMS, directing the victim to a website designed to resemble a legitimate Microsoft sign-in page.

At that point, the social engineering campaign turns into an authentication attack.

Attackers Abuse AiTM and Device-Code Authentication

One technique involved Adversary-in-the-Middle (AiTM) phishing. In simple terms, the attacker positions malicious infrastructure between the victim and the legitimate authentication service to capture useful authentication information or session tokens.

Another technique involves device-code authentication.

In this scenario, victims can be persuaded to enter an authentication code into Microsoft's legitimate authentication interface. Without realizing what is happening, they may authorize access for an attacker-controlled client.

This means the attacker does not necessarily need to steal the user's password directly.

Microsoft documented a case in which the device-code flow resulted in a compromised session token that was subsequently used to access resources available to the victim's account. 6

The Bigger Problem: Attackers Add Their Own MFA Method

Initial account access is not necessarily the end goal.

After compromising an identity, attackers can attempt to establish persistence by registering authentication methods they control.

Microsoft observed methods including phone numbers, authenticator applications, and software-based OTP tokens being added to compromised accounts.

This changes the situation significantly.

Instead of depending on the victim every time they want to access the account, attackers can create their own authentication path.

The result can be a persistent foothold inside the organization's cloud environment.

What Happens After the Account Is Compromised?

Once inside, attackers can begin mapping the Microsoft 365 environment.

Microsoft observed activity involving Microsoft Graph, where compromised identities were used to enumerate users, groups, permissions, resources, and accessible information.

Attackers also accessed SharePoint and OneDrive at high volume and collected information from mailboxes.

Depending on the amount of available data, collection activity could continue for hours or even several days.

So the objective is not simply stealing access to one email account.

A compromised Microsoft 365 identity can become a gateway to a much larger collection of corporate data.

Why Is This Attack Difficult to Spot?

The initial steps can look completely normal.

An employee receives a phone call. Then they receive a text message. They open a website and complete an authentication process.

From the employee's perspective, it may look like a routine IT procedure.

Microsoft also noted that some of the initial interaction can occur through personal devices that are not enrolled in corporate endpoint security systems, making the earliest evidence harder to detect. 7

Attackers may also research their targets before making contact. Public information from social networks and professional profiles can help them understand an organization's structure and identify employees.

Passkeys Still Matter, But Security Requests Must Be Verified

This campaign highlights an important distinction between secure technology and secure behavior.

Passkeys are designed to provide strong protection against many forms of credential theft. But no authentication technology can completely protect a user who is deliberately manipulated into approving a malicious authentication request.

That means adopting passkeys does not mean users can stop paying attention.

If you want to understand how modern password managers are adopting passkeys, our password manager guide for 2026 provides a broader look at the technology.

How to Recognize Passkey-Themed Phishing

There are several warning signs worth watching for.

  • Someone claiming to be IT suddenly asks you to update your passkey.
  • You are told to open a login link sent through SMS.
  • The website address looks similar to a legitimate service but uses an unfamiliar domain.
  • The caller creates urgency by claiming your account will soon be blocked.
  • You are asked to enter an authentication code you did not initiate yourself.
  • You are asked to add a new phone number or authentication method.

If something feels unusual, do not follow the instructions simply because the person claims to be from IT.

MFA Is Not a Magic Safety Button

Multi-factor authentication remains extremely valuable, but the authentication process itself still needs to be protected.

If a user is manipulated into approving an authentication flow that was actually initiated by an attacker, the additional security layer can become part of the attack.

Organizations therefore need to monitor more than passwords and MFA status. They should also examine who registered authentication methods, when they were added, which device was involved, and whether the activity matches the user's normal behavior.

Companies Should Review Registered Authentication Methods

Microsoft 365 administrators should pay close attention to authentication methods registered on user accounts.

An unfamiliar phone number, authenticator application, or OTP method should be investigated.

Organizations should also monitor unusual sign-ins, authentication changes, high-volume Microsoft Graph activity, and unexpected downloads from SharePoint and OneDrive.

Microsoft noted that individual Graph API requests may not look suspicious in isolation. The broader behavioral sequence is much more important. 8

Regular Users Should Be Careful Too

Although these campaigns are particularly relevant to enterprise environments, the underlying security lessons apply to ordinary users as well.

Never trust a message asking you to change account security settings simply because it appears to come from a support representative.

If you receive a security notification, open the official application or website manually instead of following a link sent through SMS, email, or an unexpected message.

And if you manage many passwords or passkeys, make sure your credentials are stored securely. Android is also making password and passkey migration between compatible password managers easier, as explained in our article about transferring passwords and passkeys without CSV files.

Phishing Is No Longer Just About Stealing Passwords

This may be the most important lesson from the campaign.

Traditional phishing often had a simple objective: convince the victim to enter a username and password on a fake website.

Modern identity attacks can go further.

Attackers can manipulate users into participating in authentication processes that ultimately authorize access for someone else.

That means modern account security is not only about creating strong passwords or enabling MFA.

Users also need to understand what they are actually approving whenever they authenticate.

Conclusion

The passkey-themed phishing campaign disclosed by Microsoft is a useful reminder that modern security technology can still be exploited through social engineering.

Passkeys themselves have not simply been “hacked.” Instead, attackers are using passkey-related terminology and authentication workflows to gain the victim's trust and guide them toward AiTM or device-code phishing.

Once access is obtained, attackers can attempt to register their own authentication methods, map the Microsoft 365 environment, access mailboxes, and collect data from services such as SharePoint and OneDrive.

For users, the basic rule is simple: never change account security settings because someone unexpectedly tells you to do so.

If there really is a problem with your account, open the official service yourself and verify the situation there.

In the passkey and MFA era, digital security is no longer just about protecting a password. Making sure you do not accidentally authorize the wrong person is becoming just as important.

Majid Abana Segaf
Majid Abana Segaf Penebar Cinta Dari Negeri Fana

Post a Comment for "Passkeys Become a Phishing Lure? Hackers Target Microsoft 365 Accounts in New Attack"