Microsoft 365 Accounts Compromised by Passkey Phishing Attacks
Threat actors have been observed using social engineering tactics to hijack Microsoft 365 accounts and steal cloud data. The attackers, who have been active since May 2026, pose as an organization's IT helpdesk and contact victims via phone call, SMS message, or Microsoft Teams message.
Their goal is to trick the victim into updating a passkey, multifactor authentication (MFA), or SSO setting, claiming that access will be lost otherwise. However, in many cases, this is just a lure, and the real objective is to capture credentials and session tokens through adversary-in-the-middle (AiTM) phishing.
Once the attackers gain access, they quickly register an authentication method under their control, such as a new phone number or Microsoft Authenticator device. This allows them to satisfy later authentication prompts without involving the victim.