Phishing Campaign Abuses Passkeys to Compromise Corporate Accounts
Microsoft has issued a warning about an ongoing social engineering campaign that uses passkey enrollment as a lure to compromise corporate accounts and steal data from Microsoft 365 services.
The attacks, observed since May 2026, begin with threat actors impersonating IT help desks and directing employees to fake Microsoft sign-in pages or device-code authentication flows.
After gaining access, attackers add their own authentication methods, use Microsoft Graph to map cloud resources, and collect data from SharePoint, OneDrive, and Exchange.
The campaign abuses passkeys as a social engineering lure rather than exploiting the technology itself.