Skip to main content
The Wire
CyberNews by Zentrya One
Cloud & AppSec

Attackers Use Passkey-Themed Phishing to Hijack Microsoft Cloud Accounts and Steal Data

Threat actors are using passkey-themed social engineering to compromise Microsoft 365 accounts and gain access to sensitive cloud data, according to Microsoft Threat Intelligence.

The campaigns, observed since May 2026, impersonate IT support personnel and convince employees that they need to configure or update a passkey, multifactor authentication (MFA), or single sign-on setting. Victims are then directed to attacker-controlled phishing infrastructure or manipulated into completing an authentication request.

The attacks demonstrate that even organizations using modern passwordless authentication can still face significant risk when attackers target the human and identity layers.

How the Attack Works

The campaigns typically begin with attackers researching employees and their organizations before contacting targets through phone calls, SMS messages or other communication channels.

Attackers impersonate IT help-desk staff and create a sense of urgency around a supposed passkey or security configuration problem.

Victims may then be directed to a fake Microsoft sign-in page or asked to complete a device-code authentication flow.

In adversary-in-the-middle scenarios, the phishing infrastructure relays authentication requests to legitimate Microsoft services while capturing credentials and session information.

In other cases, the victim may unknowingly authorize an attacker-controlled device or application.

Attack chain:

Target research → IT support impersonation → Passkey/MFA pretext → Phishing or device-code authentication → Account compromise → Cloud reconnaissance → Data collection → Exfiltration

Microsoft 365 Data Targeted

Once an account is compromised, attackers can use the victim's legitimate cloud permissions to access services such as:

  • Microsoft Exchange Online
  • SharePoint
  • OneDrive
  • Microsoft Teams
  • Microsoft Graph APIs
  • Other connected SaaS applications

Microsoft observed compromised identities being used for reconnaissance followed by activities such as new authentication-method registration, Microsoft Graph queries and large-scale downloads from cloud storage and email services.

Compromised accounts can also be used to send additional phishing messages through trusted enterprise services, helping attackers expand the campaign.

Passkeys Are Not the Vulnerability

The attacks do not demonstrate a cryptographic weakness in passkeys themselves.

Instead, attackers are abusing the familiarity of passkey and passwordless authentication to make social-engineering attempts appear legitimate.

This distinction is important: phishing-resistant authentication can significantly reduce credential theft, but organizations still need controls around account recovery, device enrollment, authentication-method changes and user-approved authentication flows.

What SOC Teams Should Monitor

Security teams should look for unusual activity immediately following suspicious help-desk interactions or authentication events.

Important indicators include:

  • New passkeys or authentication methods added unexpectedly
  • Unusual device registrations
  • Device-code authentication from unexpected locations
  • Sign-ins followed by rapid cloud reconnaissance
  • Abnormal Microsoft Graph API activity
  • Large SharePoint or OneDrive downloads
  • Unusual mailbox access
  • New OAuth applications or consent grants
  • Suspicious Teams messages sent from compromised accounts
  • Sign-ins from unfamiliar devices or locations

A particularly useful detection strategy is to correlate identity events with subsequent data-access activity rather than treating each authentication alert independently.

Recommended Defenses

Organizations should:

Strengthen help-desk verification
Require strong identity verification before changing authentication methods or registering new devices.

Monitor authentication-method changes
Alert on unexpected passkey, MFA or security-key registrations.

Restrict device-code authentication
Apply Conditional Access policies where appropriate and monitor unusual device-code flows.

Protect privileged accounts
Use phishing-resistant authentication and tightly control authentication-method changes for administrators.

Monitor cloud data access
Detect unusual downloads from SharePoint, OneDrive and Exchange following account compromise.

Train employees against IT-support impersonation
Users should never approve unexpected authentication prompts or follow security instructions from unsolicited callers without independent verification.

The campaign highlights an important shift in identity attacks: attackers do not necessarily need to steal a password when they can convince a legitimate user to authorize access for them.

For SOC teams, monitoring authentication alone is no longer sufficient. The critical signal may come from what happens immediately after authentication—particularly new authentication methods, unfamiliar devices, abnormal API activity and large-scale cloud data access.

SEO Meta Description:
Attackers are using passkey-themed phishing and social engineering to hijack Microsoft 365 accounts, bypass MFA protections and steal SharePoint, OneDrive and email data.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

Cloud & AppSec

Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

Cybercriminals and state-sponsored threat actors are increasingly using artificial intelligence to automate portions of real-world cyberattacks, with Anthropic revealing that its Claude models were incorporated into multi-stage operations involving reconnaissance, exploitation, credential theft and data exfiltration.

critical Cloud & AppSec

Google Play Early Access Abused to Distribute Thousands of Deceptive Android Apps

Cybercriminals are exploiting Google Play's Early Access program to distribute deceptive Android applications, including fake gambling platforms, financial scams, game clones and potentially malicious utilities, while taking advantage of the lack of public ratings and reviews.

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.