Passkey Phishing Attacks Bypass Microsoft 365 MFA Protections
Hackers are using passkey-themed phishing attacks to gain control of Microsoft 365 accounts and access cloud data, despite Multi-Factor Authentication (MFA) protections. The campaign begins with calls and texts to employees, posing as IT support and claiming that a passkey or MFA setting needs attention.
The attackers then direct targets to lookalike sign-in pages, which can capture credentials and session tokens. Compromised accounts can also send lures through Microsoft Teams.
Microsoft researchers identified the activity across cloud intrusions observed since May 2026. They found unusual sign-ins followed by new authentication methods, Microsoft Graph queries, and downloads from SharePoint, OneDrive, and email services.