Microsoft Warns of Passkey-Themed Phishing Attacks Stealing Data from Microsoft 365
Threat actors are using social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services, according to Microsoft. The attackers target employees by researching their organizations and contacting them via phone or messaging, pretending to be IT help desks.
The attackers trick victims into signing in to phishing sites designed to resemble legitimate Microsoft login pages, which allows the threat actors to capture credentials and session tokens. This is done through adversary-in-the-middle (AiTM) attacks or device-code authentication flows.
Microsoft notes that the attackers conduct extensive research on their targets before launching an attack, gathering information from public sources such as social networking and professional profiling platforms. The attackers also register phishing domains that combine company names with words related to passkeys, single sign-on (SSO), key synchronization, account setup, and identity verification.
Once the attackers gain access, they use Microsoft Graph to enumerate the victim's cloud environment, including organizations, licenses, users, groups, directory roles, and authentication methods. They then move into cloud data collection, accessing files, emails, and documents from Microsoft 365 services such as SharePoint Online and OneDrive for Business.