Attackers Exploit Passkey Updates for Corporate Data Access
Attackers are using social engineering campaigns to trick employees into updating their passkeys and multifactor authentication (MFA) settings, according to Microsoft Security Research. The attackers pose as IT support staff and contact victims via phone calls, text messages, or Microsoft Teams messages.
The campaigns are particularly effective in enterprise environments because the attackers research organizations, create convincing domains that reference the target company, and often use compromised internal accounts to make requests appear legitimate.
Once the attackers gain access, they quickly move beyond the initial account compromise by accessing identity management portals, enumerating applications, querying Microsoft Graph, and exploring resources across SharePoint Online, OneDrive, and Exchange Online.