Microsoft 365 Accounts Hijacked Through Fake Passkey Alerts
Microsoft 365 accounts are being compromised through fake passkey alerts sent by extortion gangs to corporate employees. These groups, linked to ShinyHunters and Helix, impersonate an organization's IT help desk via phone calls or messages, claiming that urgent updates are needed to prevent losing access to corporate systems.
The attackers then use AI-powered phishing (AiTM) pages that closely resemble legitimate Microsoft authentication pages. These pages can capture both login credentials and authenticated session tokens, allowing the attackers to take control of the account without needing another MFA challenge.
Additionally, device-code phishing is used, where attackers provide victims with a device code and convince them to enter it on Microsoft's legitimate authentication page. Once the victim approves the request, an attacker-controlled OAuth application receives an authentication token, giving the attacker access to the account.