Passkey Phishing Scams Target Microsoft 365 Accounts with Social Engineering Tactics

Sep 11, 2026 338 views

Recent phishing campaigns are exploiting themes surrounding passkeys to deceive employees into compromising their Microsoft accounts. Microsoft Security Research has been monitoring these intrusions since May, linking them to a method in which attackers impersonate IT helpdesk personnel.

The Dynamics of the Attack

In these attacks, victims receive notifications suggesting they must update or enroll a passkey. This prompts redirection to sophisticated phishing pages designed to harvest credentials. These pages typically utilize adversary-in-the-middle (AiTM) tactics or manipulate Microsoft authentication flows to collect sensitive information. Ultimately, attackers gain unauthorized access to cloud identities, enabling them to install their own authentication measures, map the victims’ Microsoft 365 ecosystems, and retrieve sensitive information stored in cloud-hosted applications.

This isn't just routine phishing; it’s a calculated strategy that leverages the latest trends in account security. Recent shifts have made passkeys a more prominent topic, especially as organizations push for enhanced methods of authentication. The irony here is sharp: passkeys designed to improve security are instead being weaponized against users. As security protocols evolve, so do the tactics employed by cybercriminals, creating a constant cat-and-mouse game.

“The passkey in this campaign is just a lure, not the vulnerability,” noted Jon Baker, VP of Threat-Informed Defense at AttackIQ. “If real passkeys were used, this wouldn’t have worked.” His statement underscores a critical aspect of the current threat landscape: cybercriminals are becoming increasingly adept at exploiting the very technologies designed to protect us. The focus on passkeys is merely a tactic, and the underlying vulnerabilities lie elsewhere.

How the Attack Initiates

The phishing attempts commonly commence with a message or call to an employee's personal device. An impostor, claiming to be part of the organization’s IT helpdesk, asserts a need to swiftly update a passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to prevent service disruption. This creates a sense of urgency, pressuring the employee to act quickly and potentially make flustered decisions.

Victims are then directed to lookalike Microsoft sign-in pages—a technique that's alarmingly effective. Depending on the attack type, the adversary can collect credentials through AiTM techniques or persuade the victim to input a code onto the legitimate Microsoft site. This often results in inadvertently granting access to the attackers. The clever engineering of these attacks means they can leave minimal traces, particularly when victims access phishing links through personal devices, which are usually less secure and not monitored by comprehensive corporate cyber defenses.

And this is the part most people overlook: some attackers leverage previously compromised accounts to send these passkey-themed messages via trusted platforms like Microsoft Teams. By masquerading as a colleague, they significantly increase the likelihood of success, as employees are more likely to trust in-house communications, even if they're designed to lead to their downfall.

Exploiting Compromised Credentials

Once an identity is breached, attackers can register their own authentication methods, such as phone numbers and authenticator apps. This sinister capability allows them to autonomously pass future MFA challenges, bypassing the need for the legitimate user's credentials entirely. It’s a chilling reminder of how easily attackers can operationalize stolen identities.

The process doesn’t end at authentication; attackers can also exploit features of Microsoft Graph, which enables them to enumerate users, groups, roles, and associated cloud resources. With this data in hand, they gain entry into SharePoint and OneDrive to exploit sensitive files, breaching Exchange Online to manipulate emails. “The actor registers their own authenticator method, maps the tenant through Microsoft Graph, and extracts files and emails at a rate that mimics normal employee behavior,” Baker explained. This meticulous approach allows attackers to blend their activities into everyday operations, significantly complicating detection efforts.

Indications of automated processes were noted. High-volume activity emanating from SharePoint and OneDrive was linked to the “python-httpx” user agent, revealing a potential underlying framework for conducting these automated attacks. Attackers maintain a subtle pace, often accessing fewer than 1,000 files or emails in an hour, an approach that enables their activities to mimic legitimate organizational behavior so closely, it becomes extraordinarily difficult for security teams to distinguish breaches from normal operations.

Countermeasures and Recommendations

To combat these increasing threats, Microsoft has offered guidance on correlating abnormal sign-ins with newly registered authentication methods and unusual operations in SharePoint, OneDrive, and Exchange. As these cyber threats escalate, a strong emphasis on adopting phishing-resistant MFA through Conditional Access is vital for mitigating risks.

Moreover, organizations should consider blocking unnecessary device-code authentication flows, as these can be gateways for further phishing attempts. Training employees on recognizing and responding to phishing attempts can also curtail the effectiveness of these tactics significantly.

Future Outlook: The War on Phishing

As digital transformation continues to accelerate, the methods employed by malicious actors will likely grow more sophisticated, more nuanced. Organizations must prepare for a future where cyber threats adapt quickly to emerging security technologies. If you're working in this space, it’s time to consider not just securing infrastructure, but embedding security awareness into the company culture.

The implications of these phishing campaigns extend beyond immediate financial or data losses; they threaten trust in digital communication as a whole. If businesses don’t act decisively, the fallout may not only damage specific organizations but could also trigger wider breaches impacting entire sectors. A proactive approach and a commitment to improved security measures may be what stands between an organization and a significant breach. The road ahead is challenging, but the response must be equally dynamic.

Source: Thomas Smith · www.csoonline.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

Attackers use passkey-themed scams to hijack Microsoft 36...