Passkey Phishing Attacks Compromise Cloud Accounts
Cyber attackers are using social engineering tactics to trick employees into divulging their passkey information, which is then used to compromise cloud accounts and gain access to sensitive data.
The attackers, often impersonating IT help desks, send fake passkey setup requests to employees' personal phones or through email messages, directing them to a website designed to resemble a legitimate Microsoft sign-in experience.
Microsoft has observed this activity since May 2026 across multiple compromised accounts and noted that the attackers' primary objective is not necessarily to enroll a passkey but rather to use it as a pretext for phishing or device-code authentication, which can capture credentials and session tokens.