{"id":420988,"date":"2026-10-01T16:10:33","date_gmt":"2026-10-01T16:10:33","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=420988"},"modified":"2026-10-01T16:10:33","modified_gmt":"2026-10-01T16:10:33","slug":"passkey-update-scam-fake-it-microsoft-365-calls","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/passkey-update-scam-fake-it-microsoft-365-calls\/","title":{"rendered":"Passkey Update Scam Exposed: Fake IT Calls That Hijack Microsoft 365 Data"},"content":{"rendered":"<p>An employee&#8217;s phone rings just as the workday gets busy. The caller knows the company name and says an account setting needs attention before the next meeting.<\/p><div id=\"mwtad3366628697\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The request sounds routine enough to postpone thinking about it. A few minutes of verification, though, can change the entire outcome.<\/p>\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Illustrative passkey update sign-in lure on a fictional domain\" class=\"wp-image-420989 lazyload\" width=\"1536\" height=\"1024\" loading=\"eager\" title=\"\" sizes=\"(max-width: 1536px) 100vw, 1536px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/passkey-hero.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/passkey-hero.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/passkey-hero-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/passkey-hero-1024x683.png 1024w\"><\/figure>\n<div id=\"mwtad2297269401\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>A familiar IT task with the wrong person behind it<\/h3>\n<p>The passkey update phishing scam begins with someone pretending to work for a company&#8217;s IT help desk. They say a passkey, MFA, or single sign-on setting needs urgent attention.<\/p><div id=\"mwtad3754210293\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The employee may get a call, message, or text link on a personal phone. The caller frames the action as routine maintenance, not an extraordinary security exception.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/09\/09\/passkey-themed-social-engineering-leads-identity-cloud-compromise\/\" target=\"_blank\" rel=\"noopener\">Microsoft Security Research reported<\/a> this pattern in active intrusions observed since May 2026. Its account connects the pretext to cloud account compromise and data access.<\/p>\n<p>Microsoft is the impersonated service, not the perpetrator. A familiar sign-in screen says nothing about who sent the link or controls the page.<\/p><div id=\"mwtad2690942738\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>The word passkey is the bait, not necessarily the objective<\/h3>\n<p>A passkey is designed to resist ordinary password theft. That strength does not protect someone who authorizes a separate login flow at a stranger&#8217;s direction.<\/p>\n<p>Microsoft says attackers in this campaign used passkey language to guide victims into adversary-in-the-middle phishing or device-code authentication. Actual passkey enrollment was often not the aim.<\/p>\n<p>The difference matters because a victim may search for a newly created passkey and miss an unauthorized session, registered sign-in method, or approved device code.<\/p><div id=\"mwtad1341366411\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>In plain English, the criminal tries to make an account trust an attacker-controlled session. The caller&#8217;s script merely supplies a believable reason to start that process.<\/p>\n<h3>The three signs to notice first<\/h3>\n<p>A real help desk can contact staff, and real organizations sometimes change sign-in settings. The suspicious part is the unplanned route and pressure to act.<\/p>\n<ul>\n<li>The contact arrives unexpectedly on a personal number.<\/li>\n<li>The caller supplies a login link or a code you did not request.<\/li>\n<li>You are told access will stop unless you act immediately.<\/li>\n<li>The process bypasses your normal IT ticket or company portal.<\/li>\n<\/ul>\n<div id=\"mwtad820042109\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>Any one detail deserves a pause. Together, they call for independent verification through the help desk number or internal channel you already know.<\/p>\n<div id=\"mwtad3470175232\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Passkey Update Phishing Scam Works<\/h2>\n<h3>Step 1: Learn enough to sound like internal support<\/h3>\n<p>The attacker may research an organization, its staff, and the tools employees use before making contact. A company website can reveal more than people expect.<\/p>\n<p>Job titles, department names, and public conference posts make a cold call feel specific. None of those details proves the caller works for IT.<\/p>\n<div id=\"mwtad4166703204\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>In some cases, the criminal reaches a personal number, which can make the conversation seem more direct. The employee may wonder how a stranger found it.<\/p>\n<p>A convincing caller may avoid technical jargon. They can simply say the company is refreshing sign-in settings and that the employee must complete a brief check.<\/p>\n<p>That language lowers resistance because legitimate IT teams do perform maintenance. The scam depends on the employee accepting the caller&#8217;s chosen path without checking it.<\/p>\n<h3>Step 2: Create a small deadline around account access<\/h3>\n<div id=\"mwtad1452796651\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The supposed help desk worker says a passkey, MFA, or SSO change must be completed now. Otherwise, the employee may lose access during the workday.<\/p>\n<p>The threat is calibrated to be annoying rather than dramatic. Missing a meeting or losing email for an hour feels plausible and costly.<\/p>\n<p>Microsoft describes calls and messages to personal phones in the observed campaign. An SMS link can arrive while the caller remains on the line.<\/p>\n<p>Staying on the phone matters. It lets the impostor answer doubts quickly and steer each click before the employee checks a separate company source.<\/p>\n<p>If the person insists that a manager or colleague cannot be consulted, the pressure itself is evidence. Legitimate authentication work does not require secrecy from security staff.<\/p>\n<h3>Step 3: Send the victim into a convincing sign-in flow<\/h3>\n<p>The link may open a page resembling a Microsoft login screen. The browser address, not the visual design, determines who controls that page.<\/p>\n<p>Another route uses a real Microsoft device-code page. The legitimate-looking location can mislead someone into thinking the entire request is trustworthy.<\/p>\n<p>Here is the crucial distinction: a real authentication page can be misused when a stranger supplies the code, timing, or purpose. The source of the request remains unverified.<\/p>\n<p>Do not type a code dictated by an unsolicited caller into a sign-in flow. End the call and ask your actual IT team whether a change was scheduled.<\/p>\n<p>In adversary-in-the-middle phishing, a criminal-controlled page can relay the sign-in to Microsoft while capturing credentials or a session token.<\/p>\n<p>Those details are not visible to the victim. The page may appear to accept a password and MFA exactly as a familiar work login does.<\/p>\n<h3>Step 4: Turn one approval into continuing access<\/h3>\n<p>Once the attacker obtains access, the problem may continue beyond the first login. Microsoft observed threat actors adding authentication methods after suspicious sign-ins.<\/p>\n<p>An added method gives the outsider another route back into the account. A password change alone may not remove every active session or unauthorized method.<\/p>\n<p>After a suspicious call, inspect account security settings for sign-in methods you did not add. Report unfamiliar entries before removing them.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Illustrative account security page with an unfamiliar authentication method\" class=\"wp-image-420990 lazyload\" width=\"1536\" height=\"1024\" loading=\"lazy\" title=\"\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/passkey-detail-v2.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/passkey-detail-v2.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/passkey-detail-v2-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/passkey-detail-v2-1024x683.png 1024w\"><\/figure>\n<p>Do not assume every newly listed method is malicious. Confirm the enrollment history with your security team, then remove anything they verify as unauthorized.<\/p>\n<p>Microsoft also describes token issuance and unusual cloud activity after initial access. These are signs administrators can examine even if the employee saw only a short phone call.<\/p>\n<p>The attacker benefits when the victim thinks the process ended after clicking Done. A quick sign-in can be the opening move of a longer intrusion.<\/p>\n<h3>Step 5: Search the cloud account for useful data<\/h3>\n<p>Microsoft observed high-volume activity involving Microsoft Graph, SharePoint, OneDrive, and email. Those services can expose documents, messages, and organization relationships.<\/p>\n<p>The attacker may look for sensitive files or conversations that support extortion, business email compromise, or access to other connected services.<\/p>\n<p>Not every suspicious login results in stolen files. The response must follow evidence, including download logs, mailbox access, and changes to account permissions.<\/p>\n<p>The employee may never see a strange program on their computer. A cloud account compromise can happen without malware installed on the personal phone used for the call.<\/p>\n<p>That is why scanning a device is useful only when there was a suspicious download. It does not replace revoking sessions and checking account activity.<\/p>\n<h3>Step 6: Use the stolen access before anyone notices<\/h3>\n<p>An attacker with access may send mail from a real company account, search for invoices, or download files. The next victim may see a genuine sender address.<\/p>\n<p>Microsoft links some of the observed activity to extortion ecosystems, but attribution differs across incidents. Avoid assuming one named group made every passkey-themed call.<\/p>\n<p>After the first report, administrators should treat the incident as an identity investigation. The person who received the call can supply vital timing and wording.<\/p>\n<p>A small recollection can matter: whether the link arrived by SMS, whether a code appeared, and whether the caller requested an MFA approval.<\/p>\n<p>Those details help the security team connect user experience to log events. Silence or embarrassment gives the attacker more time.<\/p>\n<div id=\"mwtad1546502233\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why Passkey Protection Does Not Make This Call Safe<\/h2>\n<h3>A strong login method cannot authenticate a stranger&#8217;s instructions<\/h3>\n<p>Passkeys can prevent many ordinary phishing attacks because the credential is tied to the legitimate site. That is a reason to use them, not distrust them.<\/p>\n<p>The attack described here asks a different question: can someone persuade you to approve access through another valid mechanism? Technology still relies on informed consent.<\/p>\n<p>Think of a secure door with a very good lock. The lock works, but it cannot judge a visitor you choose to admit.<\/p>\n<p>The scammer&#8217;s script tries to make their request feel like an internal maintenance order. Verification of the caller is the missing security control.<\/p>\n<h3>The company login page is only part of the chain<\/h3>\n<p>A legitimate Microsoft page can appear during a device-code flow. That alone does not show who initiated the sign-in or what access the code will grant.<\/p>\n<p>Likewise, a web page that copies Microsoft styling is not necessarily hosted by Microsoft. Compare the full address carefully, including the domain immediately before the first slash.<\/p>\n<p>Extra words such as verify, support, or secure do not make a domain official. A padlock icon only says the connection is encrypted.<\/p>\n<p>When in doubt, close the page and open your work portal using a saved bookmark. Ask the help desk through the organization&#8217;s directory.<\/p>\n<h3>A personal phone can hide the beginning of the incident<\/h3>\n<p>Microsoft notes that a phishing link opened on a personal device may not appear in the organization&#8217;s endpoint telemetry. The employee&#8217;s report can fill that gap.<\/p>\n<p>Do not wait until you can prove the page was malicious. Tell IT that an unsolicited caller directed you through an account-related process.<\/p>\n<p>If you only received the call and never followed the link, there may be no compromise. Reporting the attempted impersonation still helps warn coworkers.<\/p>\n<p>The proper response is proportional: preserve the message, verify the request, and let account logs determine whether access was granted.<\/p>\n<div id=\"mwtad3212522994\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Check a Real IT Request Without Losing Work Time<\/h2>\n<p>Ask the caller for the ticket number, but do not treat a number they provide as proof. Look it up in your own ticket system.<\/p>\n<p>Call the help desk using the number in your company directory. Do not call back the number that appeared in the incoming message.<\/p>\n<p>Check whether your organization announced an authentication change. Genuine migrations usually have a known schedule, support documentation, and a place to ask questions.<\/p>\n<p>If the change is real, ask IT to provide the approved link through the company portal. You can complete it after the independent confirmation.<\/p>\n<p>Do not share MFA codes, device codes, recovery codes, or screenshots of sign-in prompts with an unexpected caller. They are not harmless troubleshooting details.<\/p>\n<p>Be especially careful when the caller says to use your personal phone. Ask whether company policy permits that workflow and why an internal channel is unavailable.<\/p>\n<p>A legitimate help desk should understand a callback. The time spent confirming identity is smaller than the time required to investigate stolen cloud files.<\/p>\n<div id=\"mwtad3968071326\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do If You Followed a Fake Passkey Update<\/h2>\n<ol>\n<li><strong>Contact your real security team now.<\/strong> Use a known company channel. Say exactly what you approved, which link you opened, and when the call occurred.<\/li>\n<li><strong>Stop using the suspicious page.<\/strong> Close it, but preserve the SMS, caller number, screenshots, and browser history for investigators. Do not interact further with the caller.<\/li>\n<li><strong>Have IT revoke active sessions.<\/strong> A password reset alone may leave tokens or sessions valid. Ask for a full sign-out and a review of device-code activity.<\/li>\n<li><strong>Inspect authentication methods.<\/strong> Look for unfamiliar phone numbers, apps, passkeys, security keys, or registered devices. Remove only after confirming with administrators.<\/li>\n<li><strong>Change credentials through the real portal.<\/strong> Follow your organization&#8217;s incident instructions, then change reused passwords on unrelated personal accounts from a trusted device.<\/li>\n<li><strong>Review cloud and mailbox activity.<\/strong> Ask administrators to check unusual sign-ins, sharing links, mail forwarding, recent downloads, and new application permissions.<\/li>\n<li><strong>Warn affected contacts if directed.<\/strong> If your account sent messages or exposed sensitive files, the security team can coordinate notifications and required reporting.<\/li>\n<li><strong>Scan only when a file ran.<\/strong> If you downloaded software or executed a command, isolate the device and run a reputable Malwarebytes scan under IT guidance.<\/li>\n<\/ol>\n<p>AdGuard can help block some malicious web destinations and ads later, but it cannot revoke a stolen cloud session. Account containment comes first.<\/p>\n<p>If you merely answered the phone but did not approve any prompt, tell IT what happened. They can check whether another employee received the same script.<\/p>\n<p>Do not erase texts or call logs until investigators have recorded them. Their timing can connect your report to the account activity.<\/p>\n<p>When the incident is under control, ask what sign-in method was actually affected. The answer may be a device code, a token, or an unauthorized method, not a broken passkey.<\/p>\n<div id=\"mwtad2703162305\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Frequently Asked Questions<\/h2>\n<h3>Can a scammer steal my passkey through this call?<\/h3>\n<p>The reported campaign often used passkey language as a pretext. The attacker sought access through phishing or device-code flows, not necessarily the passkey itself.<\/p>\n<h3>What if the page really was hosted by Microsoft?<\/h3>\n<p>A real Microsoft authentication page can be part of a malicious device-code request. Verify who initiated the flow before entering a code or approving access.<\/p>\n<h3>Will changing my password remove the attacker?<\/h3>\n<p>Not reliably on its own. Your administrators should revoke sessions, inspect added authentication methods, and review app permissions and cloud activity.<\/p>\n<h3>Could a real IT employee contact my personal phone?<\/h3>\n<p>Possibly, depending on workplace policy. The safe test is an independent callback through the company directory or a ticket you locate yourself.<\/p>\n<h3>Do I need a malware scan after receiving the SMS?<\/h3>\n<p>Receiving or reading a text does not by itself install malware. A scan becomes relevant if you downloaded, opened, or ran a suspicious file.<\/p>\n<h3>What should I tell my coworkers?<\/h3>\n<p>Share the caller&#8217;s wording and the unverified link with your security team. Let them send a coordinated warning without circulating the malicious URL.<\/p>\n<div id=\"mwtad2469906096\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The Bottom Line<\/h2>\n<p>The passkey update story borrows a genuine security term to make an unexpected call feel routine. The danger lies in following an unverified person&#8217;s sign-in instructions.<\/p>\n<p>Hang up, verify through your real help desk, and report any approval quickly. Prompt action can close unauthorized sessions before a brief call becomes a wider breach.<\/p>\n<div id=\"mwtad967911408\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>An employee&#8217;s phone rings just as the workday gets busy. The caller knows the company name and says an account setting needs attention before the next meeting. The request sounds routine enough to postpone thinking &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Passkey Update Scam Exposed: Fake IT Calls That Hijack Microsoft 365 Data\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/passkey-update-scam-fake-it-microsoft-365-calls\/#more-420988\" aria-label=\"Read more about Passkey Update Scam Exposed: Fake IT Calls That Hijack Microsoft 365 Data\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":420989,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-420988","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/420988","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=420988"}],"version-history":[{"count":2,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/420988\/revisions"}],"predecessor-version":[{"id":421035,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/420988\/revisions\/421035"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/420989"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=420988"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=420988"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=420988"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}