Passkey Scam Used in Sophisticated Cloud-Based Intrusion Campaign
Microsoft has detected an active cloud-based intrusion campaign that involves passkey-themed social engineering and impersonation infrastructure.
The attack sequence begins with identity-focused social engineering, where a caller or message claims to be from the organization's IT helpdesk, stating that a passkey or multifactor authentication (MFA) configuration must be updated immediately to avoid disruption.
Victims are directed to a website that closely resembles a legitimate Microsoft sign-in experience, and may receive the link through SMS messages sent directly to their personal mobile phones.
The actor's true objective is not passkey enrollment but rather to guide victims through adversary-in-the-middle (AiTM) phishing or device-code authentication flows.