Passkey Phishing Campaigns Target Microsoft 365 Users
Microsoft 365 accounts are increasingly being targeted by attackers who are using passkey-themed social engineering tactics to trick users into compromising their cloud identities.
According to Channel Insider, Microsoft has observed campaigns since May 2026 where threat actors impersonate IT support to guide employees through updating security features like passkeys or multi-factor authentication.
These attacks utilize methods such as adversary-in-the-middle phishing and device code authentication to intercept credentials, steal session tokens, or authorize attacker-controlled sessions.
Once access is gained, attackers can move laterally within Microsoft 365 services like Exchange Online, SharePoint, and OneDrive for reconnaissance and data collection.
The trend highlights a broader identity security challenge where even advanced authentication methods can be bypassed through social engineering.