Passkey Phishing Campaign Targets Microsoft 365 Accounts
Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. The campaign starts with calls and texts to employees, where attackers pose as IT support claiming a passkey or MFA setting needs attention.
The attackers then direct targets to lookalike sign-in pages, which can defeat MFA protections. Compromised accounts can also send lures through Microsoft Teams.
Microsoft researchers identified the activity across cloud intrusions observed since May 2026 and found unusual sign-ins followed by new authentication methods, Microsoft Graph queries, and downloads from SharePoint, OneDrive, and email services.