Passkey Phishing Campaign Targets Employee Identities, Gains Cloud Access
Microsoft has issued a warning to organizations about an active social engineering campaign that targets employee identities and gains access to corporate cloud data. The attackers impersonate IT help desks and use fake passkey setup requests to compromise employee identities.
The attacks have been observed since May 2026, with victims receiving phone calls or messages sent to their personal phones. The attacker poses as someone from the organization's IT help desk, telling the victim that a passkey or multifactor authentication (MFA) configuration needs to be updated to avoid disruption.
Despite the passkey-themed approach, Microsoft stressed that enrolling a passkey is generally not the attacker's actual objective. Instead, the request provides a pretext for directing victims through adversary-in-the-middle phishing or device-code authentication.
In one attack investigated by Microsoft, an anomalous sign-in from an unmanaged device was followed by access to identity and application management services. The attacker then used SharePoint Online and OneDrive to enumerate sensitive files, primarily through Microsoft Graph.