Microsoft Warns of Passkey Phishing Attacks on Microsoft 365 Accounts
Microsoft has issued a warning about passkey phishing attacks that target Microsoft 365 accounts. These attacks use social engineering to trick users into revealing sensitive information, allowing attackers to gain access to cloud services such as Exchange Online, SharePoint, and OneDrive.
The campaigns typically involve attackers impersonating IT support staff and contacting employees with instructions to update or configure security features, including passkeys and multifactor authentication. Once access is obtained, attackers can move deeper into the victim's Microsoft cloud environment, using techniques such as adversary-in-the-middle phishing and device code authentication.
Microsoft has observed these attacks since at least May 2026 and recommends that organizations investigate suspicious sign-ins, unexpected registrations of authentication methods, unusual device code activity, and abnormal activity across Microsoft 365 services. Partners managing Microsoft environments should also consider whether customers actually need device code authentication and monitor for unexpected changes in authentication methods.