Passkeys are designed to make online accounts safer by reducing reliance on passwords and resisting traditional phishing. But attackers are now flipping that security message against users.
A new phishing campaign is using passkey, MFA, and SSO-related themes to trick employees into handing over access to their Microsoft 365 accounts and cloud data. Microsoft researchers identified the activity across cloud intrusions observed since May 2026.
The attack often begins with a phone call or text message pretending to be from IT support. Victims are told that their passkey, MFA, or single sign-on settings require an urgent update. They are then directed to a fake sign-in page designed to look legitimate.
The dangerous part is what happens next. Instead of simply stealing a password, attackers can use adversary-in-the-middle (AiTM) phishing to relay the victim’s authentication to the real Microsoft service while capturing credentials and session tokens. In other cases, attackers abuse device-code authentication, allowing them to obtain a token that can later be replayed.
That means even completing MFA does not necessarily mean the account is safe.
Once inside, attackers work to establish persistence by registering their own phone number, authenticator app, or software-based OTP method. They then use Microsoft Graph to map the compromised environment, searching through users, groups, permissions, applications, SharePoint sites, OneDrive files, and mailboxes.
The campaign can ultimately turn a seemingly harmless “passkey update” into a cloud data theft operation. Attackers have been observed downloading files from SharePoint and OneDrive and accessing Exchange Online email data, often at a controlled pace that can blend into normal activity.
For organizations, the lesson is simple: a security-themed message is not automatically a security message.
Employees should verify unexpected IT calls through a trusted internal channel and avoid authentication links provided by callers or text messages. Security teams should also monitor unusual sign-ins followed by new MFA registrations, extensive Graph activity, and suspicious cloud downloads.
Passkeys may be phishing-resistant, but the human trust surrounding them can still be exploited.
Let’s refine your stalking skills; go through our Instagram and LinkedIn.