Microsoft Warns of Phishing Tactic Using Fake Passkey Setup Requests
Microsoft has issued a warning about a new phishing tactic being used to compromise work accounts. In a security investigation, Microsoft found that attackers are using fake passkey setup requests to lure employees into sign-in traps and gain access to their work accounts.
The attackers may contact the employee on their personal phone, pretending to be the company's IT helpdesk, and ask them to set up a passkey or update their sign-in settings immediately. The request may come in the form of a call, text message, or workplace message that appears to come from a familiar channel.
Microsoft notes that the attackers' real objective is not to steal the passkey itself, but to use it as a way to capture credentials or session tokens. In some cases, the attackers may add authentication methods under their control, such as a phone number or authenticator method, so they can satisfy later sign-in challenges.
Microsoft advises employees to be cautious when receiving unexpected setup requests and to verify them through an IT contact or channel they already know. If you receive such a request, do not rely on the phone number or link supplied in the message to confirm it, and be especially cautious if someone asks you to enter a device code or approve a sign-in you did not start.