Passkey Scams Used to Hijack Microsoft 365 Accounts
Attackers are using passkey-themed social engineering to trick employees into giving them access to their Microsoft accounts. According to Microsoft Security Research, attackers have been impersonating IT helpdesk staff since May, telling employees they need to update or enroll a passkey.
The attackers then take the victims to adversary-in-the-middle (AiTM) phishing pages or Microsoft device-code authentication flows. This allows them to gain access to compromised cloud identities and register their own authentication methods.
Microsoft has recommended correlating unusual sign-ins with new authentication method registrations, Graph reconnaissance, and abnormal SharePoint, OneDrive, and Exchange activity. The company also advises enforcing phishing-resistant MFA via Conditional Access and blocking device-code and authentication-transfer flows where there is no legitimate business need.
'The passkey in this campaign is the lure, not the weakness,' said Jon Baker, VP of Threat-Informed Defense at AttackIQ. 'The MFA that got bypassed was phishable. Real passkeys would have stopped it.'