Cybercriminals are adopting passkey-themed phishing techniques to gain unauthorized access to Microsoft 365 accounts, allowing them to steal valuable cloud data. This strategy poses a significant threat as it can bypass multi-factor authentication (MFA) protections.
Phishing Techniques Targeting Microsoft Accounts
The attack initiates through phone calls or text messages directed at employees. Hackers impersonate IT support personnel, claiming there is an issue with passkey, MFA, or single sign-on settings that requires immediate attention. Victims are then guided to fraudulent sign-in pages resembling legitimate ones.
Once an account is compromised, attackers can further exploit Microsoft Teams to distribute additional phishing lures. Microsoft researchers have observed this malicious activity in cloud intrusions since May 2026, characterized by unusual sign-ins, the introduction of new authentication methods, and unauthorized data downloads from SharePoint, OneDrive, and email services.
Understanding the Phishing Strategy
According to a Microsoft report shared with Cyber Security News, attackers frequently rotate their infrastructure and use separate connections for different stages of the attack. This approach allows them to blend in with regular user activity while mapping out organizational data and exfiltrating files and messages.
The passkey narrative serves merely as a pretext, not an actual attempt to enroll a passkey. Victims may find themselves in an adversary-in-the-middle attack, where a deceptive site relays their login information to the real service, capturing credentials and session tokens in the process. In some cases, a device-code sign-in might be completed, providing attackers with control over a session.
Impact and Defense Strategies
Once inside, attackers aim to establish persistent access by adding phone numbers or authenticator apps under their control. A simple password reset may not suffice to evict them if active sessions or rogue authentication methods remain. Organizations should scrutinize all new authentication factors and investigate any risky sign-ins.
Microsoft’s findings highlight the importance of confirming unexpected helpdesk requests through verified internal channels. Employees are advised to avoid using numbers or links provided by unverified sources and to report suspicious authentication requests promptly.
As attackers gain persistence, they exploit Microsoft Graph to explore accessible resources, including users, groups, applications, and files. They perform high-volume downloads from SharePoint Online and OneDrive for Business, and in some cases, access email content via the Exchange Online REST API. This activity, often below 1,000 items per hour, can evade detection while continuing for extended periods.
Preventive Measures for Organizations
Organizations should correlate identity, Graph, SharePoint, OneDrive, and Exchange activity to detect anomalies. Key indicators of compromise include unusual sign-ins followed by MFA enrollment, intensive Graph queries, and high-volume data downloads.
To mitigate these risks, teams need to revoke active sessions, reset compromised credentials, remove unauthorized authentication methods, and enforce secure MFA registration. Limiting cloud access from unmanaged devices and controlling device-code flows can further strengthen security postures.
Training staff on recognizing phishing attempts via voice, text, and Teams, combined with thorough cloud and mailbox audits, can prevent seemingly routine updates from escalating into major data breaches. By prioritizing phishing-resistant MFA and vigilant monitoring, organizations can fortify their defenses against evolving cyber threats.
