Attackers Use Passkey-Themed Phishing to Hijack Microsoft Cloud Accounts and Steal Data
Threat actors are using passkey-themed social engineering to compromise Microsoft 365 accounts and gain access to sensitive cloud data, according to Microsoft Threat Intelligence.

The campaigns, observed since May 2026, impersonate IT support personnel and convince employees that they need to configure or update a passkey, multifactor authentication (MFA), or single sign-on setting. Victims are then directed to attacker-controlled phishing infrastructure or manipulated into completing an authentication request.
The attacks demonstrate that even organizations using modern passwordless authentication can still face significant risk when attackers target the human and identity layers.
How the Attack Works
The campaigns typically begin with attackers researching employees and their organizations before contacting targets through phone calls, SMS messages or other communication channels.
Attackers impersonate IT help-desk staff and create a sense of urgency around a supposed passkey or security configuration problem.
Victims may then be directed to a fake Microsoft sign-in page or asked to complete a device-code authentication flow.
In adversary-in-the-middle scenarios, the phishing infrastructure relays authentication requests to legitimate Microsoft services while capturing credentials and session information.
In other cases, the victim may unknowingly authorize an attacker-controlled device or application.
Attack chain:
Target research → IT support impersonation → Passkey/MFA pretext → Phishing or device-code authentication → Account compromise → Cloud reconnaissance → Data collection → Exfiltration
Microsoft 365 Data Targeted
Once an account is compromised, attackers can use the victim's legitimate cloud permissions to access services such as:
- Microsoft Exchange Online
- SharePoint
- OneDrive
- Microsoft Teams
- Microsoft Graph APIs
- Other connected SaaS applications
Microsoft observed compromised identities being used for reconnaissance followed by activities such as new authentication-method registration, Microsoft Graph queries and large-scale downloads from cloud storage and email services.
Compromised accounts can also be used to send additional phishing messages through trusted enterprise services, helping attackers expand the campaign.
Passkeys Are Not the Vulnerability
The attacks do not demonstrate a cryptographic weakness in passkeys themselves.
Instead, attackers are abusing the familiarity of passkey and passwordless authentication to make social-engineering attempts appear legitimate.
This distinction is important: phishing-resistant authentication can significantly reduce credential theft, but organizations still need controls around account recovery, device enrollment, authentication-method changes and user-approved authentication flows.
What SOC Teams Should Monitor
Security teams should look for unusual activity immediately following suspicious help-desk interactions or authentication events.
Important indicators include:
- New passkeys or authentication methods added unexpectedly
- Unusual device registrations
- Device-code authentication from unexpected locations
- Sign-ins followed by rapid cloud reconnaissance
- Abnormal Microsoft Graph API activity
- Large SharePoint or OneDrive downloads
- Unusual mailbox access
- New OAuth applications or consent grants
- Suspicious Teams messages sent from compromised accounts
- Sign-ins from unfamiliar devices or locations
A particularly useful detection strategy is to correlate identity events with subsequent data-access activity rather than treating each authentication alert independently.
Recommended Defenses
Organizations should:
Strengthen help-desk verification
Require strong identity verification before changing authentication methods or registering new devices.
Monitor authentication-method changes
Alert on unexpected passkey, MFA or security-key registrations.
Restrict device-code authentication
Apply Conditional Access policies where appropriate and monitor unusual device-code flows.
Protect privileged accounts
Use phishing-resistant authentication and tightly control authentication-method changes for administrators.
Monitor cloud data access
Detect unusual downloads from SharePoint, OneDrive and Exchange following account compromise.
Train employees against IT-support impersonation
Users should never approve unexpected authentication prompts or follow security instructions from unsolicited callers without independent verification.
The campaign highlights an important shift in identity attacks: attackers do not necessarily need to steal a password when they can convince a legitimate user to authorize access for them.
For SOC teams, monitoring authentication alone is no longer sufficient. The critical signal may come from what happens immediately after authentication—particularly new authentication methods, unfamiliar devices, abnormal API activity and large-scale cloud data access.
SEO Meta Description:
Attackers are using passkey-themed phishing and social engineering to hijack Microsoft 365 accounts, bypass MFA protections and steal SharePoint, OneDrive and email data.
Related reporting
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic says it identified and disrupted seven industrial-scale attempts to extract capabilities from its Claude AI models, attributing the activity to China-based AI laboratories.
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Cybercriminals and state-sponsored threat actors are increasingly using artificial intelligence to automate portions of real-world cyberattacks, with Anthropic revealing that its Claude models were incorporated into multi-stage operations involving reconnaissance, exploitation, credential theft and data exfiltration.
Google Play Early Access Abused to Distribute Thousands of Deceptive Android Apps
Cybercriminals are exploiting Google Play's Early Access program to distribute deceptive Android applications, including fake gambling platforms, financial scams, game clones and potentially malicious utilities, while taking advantage of the lack of public ratings and reviews.


