{"id":9458,"date":"2026-09-11T09:51:37","date_gmt":"2026-09-11T09:51:37","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9458"},"modified":"2026-09-11T09:51:37","modified_gmt":"2026-09-11T09:51:37","slug":"attackers-use-passkey-themed-scams-to-hijack-microsoft-365-accounts","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9458","title":{"rendered":"Attackers use passkey-themed scams to hijack Microsoft 365 accounts"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Attackers are using passkey-themed social engineering to trick employees into giving them access to their Microsoft accounts.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft Security Research said it has been tracking active cloud intrusions since May in which attackers impersonated IT helpdesk staff, told employees they needed to update or enroll a <a href=\"https:\/\/www.csoonline.com\/article\/2513273\/passkeys-arent-attack-proof-not-until-properly-implemented.html\" target=\"_blank\" rel=\"noopener\">passkey<\/a>, and then took them to adversary-in-the-middle (<a href=\"https:\/\/www.csoonline.com\/article\/4163886\/stopping-aitm-attacks-the-defenses-that-actually-work-after-authentication-succeeds.html\" target=\"_blank\" rel=\"noopener\">AiTM<\/a>) phishing pages or Microsoft device-code authentication flows.<\/p>\n<p class=\"wp-block-paragraph\">The campaign ultimately gave attackers access to compromised cloud identities, allowing them to register their own authentication methods, map the victim\u2019s Microsoft 365 environment, and access cloud-hosted files and emails.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe passkey in this campaign is the lure, not the weakness,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/jonathanobaker\/\" target=\"_blank\" rel=\"noopener\">Jon Baker<\/a>, VP of Threat-Informed Defense at AttackIQ. \u201cThe MFA that got bypassed was phishable. Real passkeys would have stopped it.\u201d<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Identity compromised through a helpdesk call<\/h2>\n<p class=\"wp-block-paragraph\">The attacks commonly begin with a phone call or message to an employee\u2019s personal mobile number from someone claiming to be from the organization\u2019s IT helpdesk. The attacker tells the employee that a passkey, <a href=\"https:\/\/www.csoonline.com\/article\/3535222\/mfa-adoption-is-catching-up-but-is-not-quite-there.html\">MFA<\/a> or SSO configuration needs to be updated immediately to avoid disruption.<\/p>\n<p class=\"wp-block-paragraph\">The victim is then redirected to a website that resembles a Microsoft sign-in page. In AiTM attacks, the adversary can capture credentials and session tokens. In device-code attacks, the victim is instead told to enter a code on a legitimate Microsoft authentication page, authorizing an attacker-controlled client.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft says the initial interaction can leave little endpoint evidence, particularly when the victim opens the phishing link on a personal device that is not managed by Microsoft Defender for Endpoint.<\/p>\n<p class=\"wp-block-paragraph\">In some cases, attackers also used already-compromised accounts to send passkey-themed messages via Microsoft Teams, making the requests appear to come from a trusted colleague.<\/p>\n<p class=\"wp-block-paragraph\">The campaign is not limited to a single attack pattern. Microsoft also observed cases in which attackers used credentials and MFA methods that had apparently been registered days earlier, suggesting that MFA persistence had already been established.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Attackers registered their own authentication methods<\/h2>\n<p class=\"wp-block-paragraph\">Once an identity was compromised, Microsoft observed attackers registering authentication methods under their control, including phone numbers, authenticator applications, and software-based OTP tokens. This gave them a way to satisfy future MFA challenges without the legitimate user.<\/p>\n<p class=\"wp-block-paragraph\">Attackers then used Microsoft Graph to enumerate users, groups, roles, authentication methods, applications, and cloud resources. They subsequently moved into SharePoint and OneDrive to locate and access files, while some intrusions involved Exchange Online and REST API-based access to email.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe actor registers their own authenticator method, maps the tenant through Microsoft Graph, and pulls files and mail at a pace that reads like a busy employee,\u201d Baker said. \u201cNone of those calls is suspicious on its own. The sequence is.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Signs of automation were observed in some cases, including the \u201cpython-httpx\u201d user agent associated with high-volume <a href=\"https:\/\/www.csoonline.com\/article\/4197775\/cisa-urges-immediate-sharepoint-hardening-as-exploits-mount.html\">SharePoint<\/a> and OneDrive activity. Attackers also maintained a controlled pace, with fewer than 1000 files or emails accessed in an hour, potentially allowing the activity to blend into normal enterprise behavior. <\/p>\n<p class=\"wp-block-paragraph\">Microsoft has recommended correlating unusual sign-ins with new authentication method registrations, Graph reconnaissance, and abnormal SharePoint, OneDrive, and Exchange activity. It also advised enforcing phishing-resistant MFA via Conditional Access and blocking device-code and authentication-transfer flows where there is no legitimate business need.<\/p>\n<p class=\"wp-block-paragraph\">\n<\/p><\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Attackers are using passkey-themed social engineering to trick employees into giving them access to their Microsoft accounts. Microsoft Security Research said it has been tracking active cloud intrusions since May in which attackers impersonated IT helpdesk staff, told employees they needed to update or enroll a passkey, and then took them to adversary-in-the-middle (AiTM) phishing [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9459,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9458","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9458"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9458"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9458\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9459"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9458"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9458"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}