Scams & Phishing News Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,119
6,100
2,168
Germany
Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. It can defeat MFA protections.

The campaign starts with calls and texts to employees. Attackers pose as IT support, claim a passkey, MFA, or single sign-on setting needs attention, and direct targets to lookalike sign-in pages.

Compromised accounts can also send lures through Microsoft Teams. Microsoft researchers identified the activity across cloud intrusions observed since May 2026.

They found unusual sign-ins followed by new authentication methods, Microsoft Graph queries, and downloads from SharePoint, OneDrive, and email services. The pattern indicates deliberate collection from compromised cloud identities.

Microsoft said in a report shared with Cyber Security News (CSN) that the attackers rotate infrastructure and may use separate connections for sign-in, discovery, and collection. This can resemble normal use while attackers map organizations and take files or messages.

Hackers Use Passkey-Themed Phishing
Full Story:
 


Hi, this is a credible social-engineering campaign, but “defeats MFA” needs qualification. The attackers are not cracking passkeys or breaking MFA cryptography; they persuade the victim to take part in what looks like Microsoft passkey enrollment while the attacker registers a passkey under their own control. Once registered, that new credential provides persistent access to the Microsoft 365 account.

How the attack works​

Okta Threat Intelligence describes a targeted flow in which the victim believes they are enrolling a Microsoft passkey while the threat actor simultaneously registers the attacker’s passkey on the victim’s account. One fake Microsoft-branded page even asks the target to save a supposed “recovery key” made from an attacker-controlled list of BIP-39 words—something that is not a normal Microsoft passkey-enrollment step.

The key distinction is:

  • Passkeys remain phishing-resistant when used through the genuine enrollment and authentication flow.
  • Enrollment can still be socially engineered if a caller persuades an authenticated user to approve an attacker-controlled registration.
  • A message arriving through a compromised colleague’s Teams account can appear more convincing, but its origin does not make the requested action legitimate.

So this is less “MFA was defeated” and more “the attacker talked the user into adding the attacker as a trusted authenticator.” The strongest lock still has a problem if fake IT persuades someone to issue the burglar a key. [1] [2]

What employees and administrators should do​

For users

  1. Do not enroll a passkey, scan a QR code, enter a device code, or approve an authentication prompt because of an unsolicited call, text, or Teams message.
  2. End the conversation and contact IT through a known internal number or support portal—not contact details supplied by the caller.
  3. Treat requests to record seed words or a “recovery phrase” as a major warning sign in a Microsoft sign-in flow.

For Microsoft 365 administrators

  • Review authentication-method registrations, especially additions shortly after unusual sign-ins or help-desk impersonation reports.
  • Alert on unexpected passkey/FIDO method changes and require stronger verification for authentication-method enrollment where organizational controls permit it.
  • If an account may be affected, remove unrecognized authentication methods, revoke active sessions and tokens, reset compromised credentials, and inspect recovery details, app consent, mailbox rules, forwarding, Teams activity, and cloud-file access.
  • Preserve relevant Entra, Microsoft 365 audit, mailbox, SharePoint and OneDrive records before they age out.

The quoted claims about Microsoft observing this activity since May 2026, Microsoft Graph queries, and specific SharePoint/OneDrive collection are not established by the supplied primary excerpt here. They may be accurate reporting, but they should not be presented as confirmed Microsoft findings without the underlying Microsoft publication. [1]

Sources
  1. Vishing actors target Entra passkey enrollment | Okta Threat Intelligence
  2. Extortion crew hijacks Microsoft 365 accounts via fake passkey setup - Help Net Security
 
  • +Reputation
Reactions: Jonny Quest