Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Cisco ASA, FTD Critical Flaw CVE-2024-20353 Lets Attackers Gain Root Access
September 10, 2026
Passkey Phishing Attacks Hijack Microsoft 365 Accounts, Steal Cloud Data
September 10, 2026
Critical Check Point VPN Vulnerabilities Allow RCE Attacks
September 10, 2026
Home/CyberSecurity News/Passkey Phishing Attacks Hijack Microsoft 365 Accounts, Steal Cloud Data
CyberSecurity News

Passkey Phishing Attacks Hijack Microsoft 365 Accounts, Steal Cloud Data

Key Takeaways A new phishing campaign targets Microsoft 365 users, leveraging passkey-themed social engineering to compromise accounts. Attackers bypass multi-factor authentication (MFA) by stealing...

Emy Elsamnoudy
Emy Elsamnoudy
September 10, 2026 3 Min Read
4 0

Key Takeaways

  • A new phishing campaign targets Microsoft 365 users, leveraging passkey-themed social engineering to compromise accounts.
  • Attackers bypass multi-factor authentication (MFA) by stealing session tokens or tricking users into device code approvals.
  • Compromised accounts are used for extensive data reconnaissance and exfiltration from SharePoint, OneDrive, and Exchange.
  • The campaign, identified by Microsoft researchers since May 2026, employs rotating infrastructure to evade detection.
  • Organizations must implement phishing-resistant MFA and enhance monitoring for unusual sign-ins and authentication method registrations.

Cybercriminals are actively exploiting passkey-themed phishing tactics to seize control of Microsoft 365 accounts and exfiltrate sensitive cloud data. This sophisticated campaign has demonstrated the ability to circumvent robust multi-factor authentication (MFA) protections.

Table Of Content

  • Key Takeaways
  • Hackers Use Passkey-Themed Phishing
  • From Account Access to Cloud Collection

The attack typically commences with social engineering, where employees receive calls or text messages from individuals impersonating IT support. These imposters claim that passkey, MFA, or single sign-on (SSO) settings require immediate attention, directing targets to meticulously crafted, deceptive sign-in pages. Once an account is compromised, the attackers can further propagate their malicious lures internally via Microsoft Teams.

Microsoft researchers have been tracking this activity across various cloud intrusions since May 2026. Their analysis revealed a consistent pattern: anomalous sign-in events followed by the registration of new authentication methods, subsequent queries to Microsoft Graph for reconnaissance, and large-scale data downloads from SharePoint, OneDrive, and email services. This sequence strongly indicates a deliberate and systematic effort to collect data from hijacked cloud identities.

In a report shared with Cyber Security News (CSN), Microsoft said in a report that the threat actors frequently rotate their infrastructure and may utilize distinct connections for different phases of the attack, such as initial sign-in, discovery, and data exfiltration. This tactic allows their activities to blend with legitimate user behavior, making it harder for organizations to detect while the attackers systematically map organizational structures and steal files or messages.

Hackers Use Passkey-Themed Phishing

The passkey narrative serves as a deceptive lure, not an actual attempt to enroll a legitimate passkey. Victims are often directed into an adversary-in-the-middle (AiTM) phishing flow, where a malicious website acts as a proxy, relaying the victim’s sign-in credentials to the authentic service while simultaneously capturing their credentials and session tokens.

Alternatively, users might be manipulated into completing a device-code sign-in, which grants access to an attacker-controlled client. This means that even if a user successfully completes MFA, they can still inadvertently surrender a usable cloud session to the attackers. Previous BigBear session theft campaigns have demonstrated that phishing sites can steal proof of completed MFA. This underscores the critical need to scrutinize authentication prompts with the same vigilance as password requests, especially following an unexpected call or text.

In one observed attack, an attacker logged in from an unmanaged device and then used the same session to access various account portals. Another instance involved device-code approval leading to a token replay that bypassed MFA. Researchers also noted instances where attackers returned using previously compromised credentials in conjunction with an authenticator method they had registered earlier.

Upon gaining initial access, threat actors prioritize establishing persistent access. They achieve this by registering a phone number, an authenticator application, or a software one-time-password (OTP) token under their control. A simple password reset may not be sufficient to evict these attackers if active sessions, refresh tokens, or rogue authentication methods remain in place. Security teams must therefore investigate any suspicious sign-ins in conjunction with newly registered authentication factors.

Organizations have previously encountered Entra passkey enrollment attacks that leverage phone impersonation. Employees should always verify unexpected helpdesk requests through a known, official internal channel, never relying on a number or link provided by the caller. Establishing a verified reporting route for authentication requests can effectively neutralize such attacks before access is granted.

From Account Access to Cloud Collection

Once persistence is established, attackers leverage Microsoft Graph to enumerate the compromised user’s accessible resources. This includes a thorough discovery of users

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachHackerphishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Check Point VPN Vulnerabilities Allow RCE Attacks

Next Post

Cisco ASA, FTD Critical Flaw CVE-2024-20353 Lets Attackers Gain Root Access

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Palo Alto PAN-OS Critical Vulnerability Lets Attackers Execute Code as Root
September 10, 2026
OpenSSL 4.1.0 Alpha1 Released With DTLS 1.3 and Faster Post-Quantum Crypto
September 10, 2026
Critical Active Directory Flaw Lets Attackers Impersonate Domain Controllers
September 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us