Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. It can defeat MFA protections.
The campaign starts with calls and texts to employees. Attackers pose as IT support, claim a passkey, MFA, or single sign-on setting needs attention, and direct targets to lookalike sign-in pages.
Compromised accounts can also send lures through Microsoft Teams. Microsoft researchers identified the activity across cloud intrusions observed since May 2026.
They found unusual sign-ins followed by new authentication methods, Microsoft Graph queries, and downloads from SharePoint, OneDrive, and email services. The pattern indicates deliberate collection from compromised cloud identities.
Microsoft said in a report shared with Cyber Security News (CSN) that the attackers rotate infrastructure and may use separate connections for sign-in, discovery, and collection. This can resemble normal use while attackers map organizations and take files or messages.
Hackers Use Passkey-Themed Phishing