Passkey-Blind Phishers Hijack Microsoft Cloud Accounts
Cybercriminals have been exploiting confusion surrounding passkeys and single sign-on systems to compromise enterprise Microsoft accounts, according to an investigation by Microsoft Security Research.
The attackers use passkey registration, multifactor authentication updates, and security migrations as convincing social-engineering pretexts to manipulate victims into completing authentication actions that provide the attackers with valid Microsoft cloud sessions.
The campaign demonstrates how attackers are adapting to the wider corporate adoption of passwordless authentication. Rather than necessarily attacking passkey technology itself, criminals are changing the story presented to employees.