Researchers warn: Passkey phishing attacks are leading to cloud account takeover
In an active social engineering campaign, attackers are impersonating IT help desks and using fake passkey setup requests to compromise employee identities and gain access to enterprise cloud data.
In a recent blog post, Microsoft Security Research said it had observed activity in several compromised accounts since May 2026.
Attacks include unusual sign-ins, authentication methods added by the attacker, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and e-mail collection via REST APIs.
Attacks often begin with a phone call or message sent to an employee’s personal phone.
The attacker poses as someone from the organization’s IT help desk and tells the victim that the passkey, multifactor authentication (MFA), or single sign-on configuration needs to be updated to avoid disruption.
Victims are then directed to a website designed to resemble a legitimate Microsoft sign-in experience.
Microsoft has also observed that links are being distributed through SMS messages and, in some cases, through Microsoft Teams messages sent from already compromised employee accounts.
Despite the passkey-themed approach, the tech company stressed that deprogramming the passkey is typically not an attacker’s real objective.
Instead, the request provides an excuse to direct victims through man-in-the-middle phishing or device-code authentication.
An adversary in the middle attack can capture credentials and session tokens, while device-code phishing can trick a victim into authorizing access to an attacker-controlled client.
In one attack investigated by the tech giant, access to identity and application management services was gained following an unusual sign-in from an unmanaged device.
The attacker then used SharePoint Online and OneDrive to enumerate sensitive files, primarily through Microsoft Graph. The session continued for about an hour while the attacker continued searching for sensitive files and internal applications.
Gaining initial access is not necessarily the end of an identity attack.
Microsoft found that attackers are registering new authentication methods under their control, including phone numbers, authenticator apps, and software-based one-time password tokens.
This gives the attacker another way to accomplish future authentication challenges and helps the initial compromise gain a more consistent foothold.
From there, the attackers used Microsoft Graph to map users, groups, permissions, applications, and accessible content across compromised tenants.
The firm says the activity could eventually progress to accessing mail, files, attachments, and other document content.
Microsoft attributed the initial access activity associated with the campaign to multiple threat actors, including Storm-3121 and Storm-3032.
Storm-3121 conducts early access activity that could lead to ShinyHunters and Falcon extortion, while Storm-3032 represents actors who have splintered from the blackfile group and now operate under the Helix Extortion banner.
For administrators, Microsoft recommends implementing phishing-resistant MFA such as FIDO2 passkeys and Windows Hello for business through conditional access.
Organizations should also consider blocking device-code and authentication-transfer flows where they are not needed and investigate new authentication methods, graph reconnaissance, and unusual sign-ins following unusual SharePoint, OneDrive, or mailbox activity.
This campaign highlights an important difference for organizations adopting passkeys: attackers are not necessarily defeating the technology. They’re convincing employees that they need help setting it up, then using that trust to compromise their identity.
Read the Microsoft blog post for more details.
(TagstoTranslate)Microsoft(T)Passkey Phishing(T)Phishing

