Hackers Exploit Passkey Updates for Phishing
Microsoft has discovered that hackers are using passkey updates as a new phishing hook to trick employees into approving unauthorized login attempts. According to Microsoft, attackers have been impersonating IT staff and telling employees they need to update their passkeys or multifactor authentication settings.
The attackers then use this information to gain access to the employee's account, allowing them to conduct reconnaissance, add authentication methods for persistence, and access data across services including SharePoint, OneDrive, and Exchange Online.
Microsoft attributes the activity to several threat actors, including Storm-3121 and Storm-3032. The company warns that organizations should remain alert and take steps to protect themselves from these types of attacks.