Passkey Phishing Attacks Hijack Microsoft 365 Accounts, Steal Cloud Data
Key Takeaways A new phishing campaign targets Microsoft 365 users, leveraging passkey-themed social engineering to compromise accounts. Attackers bypass multi-factor authentication (MFA) by stealing...
Key Takeaways
- A new phishing campaign targets Microsoft 365 users, leveraging passkey-themed social engineering to compromise accounts.
- Attackers bypass multi-factor authentication (MFA) by stealing session tokens or tricking users into device code approvals.
- Compromised accounts are used for extensive data reconnaissance and exfiltration from SharePoint, OneDrive, and Exchange.
- The campaign, identified by Microsoft researchers since May 2026, employs rotating infrastructure to evade detection.
- Organizations must implement phishing-resistant MFA and enhance monitoring for unusual sign-ins and authentication method registrations.
Cybercriminals are actively exploiting passkey-themed phishing tactics to seize control of Microsoft 365 accounts and exfiltrate sensitive cloud data. This sophisticated campaign has demonstrated the ability to circumvent robust multi-factor authentication (MFA) protections.
Table Of Content
The attack typically commences with social engineering, where employees receive calls or text messages from individuals impersonating IT support. These imposters claim that passkey, MFA, or single sign-on (SSO) settings require immediate attention, directing targets to meticulously crafted, deceptive sign-in pages. Once an account is compromised, the attackers can further propagate their malicious lures internally via Microsoft Teams.
Microsoft researchers have been tracking this activity across various cloud intrusions since May 2026. Their analysis revealed a consistent pattern: anomalous sign-in events followed by the registration of new authentication methods, subsequent queries to Microsoft Graph for reconnaissance, and large-scale data downloads from SharePoint, OneDrive, and email services. This sequence strongly indicates a deliberate and systematic effort to collect data from hijacked cloud identities.
In a report shared with Cyber Security News (CSN), Microsoft said in a report that the threat actors frequently rotate their infrastructure and may utilize distinct connections for different phases of the attack, such as initial sign-in, discovery, and data exfiltration. This tactic allows their activities to blend with legitimate user behavior, making it harder for organizations to detect while the attackers systematically map organizational structures and steal files or messages.
Hackers Use Passkey-Themed Phishing
The passkey narrative serves as a deceptive lure, not an actual attempt to enroll a legitimate passkey. Victims are often directed into an adversary-in-the-middle (AiTM) phishing flow, where a malicious website acts as a proxy, relaying the victim’s sign-in credentials to the authentic service while simultaneously capturing their credentials and session tokens.
Alternatively, users might be manipulated into completing a device-code sign-in, which grants access to an attacker-controlled client. This means that even if a user successfully completes MFA, they can still inadvertently surrender a usable cloud session to the attackers. Previous BigBear session theft campaigns have demonstrated that phishing sites can steal proof of completed MFA. This underscores the critical need to scrutinize authentication prompts with the same vigilance as password requests, especially following an unexpected call or text.
In one observed attack, an attacker logged in from an unmanaged device and then used the same session to access various account portals. Another instance involved device-code approval leading to a token replay that bypassed MFA. Researchers also noted instances where attackers returned using previously compromised credentials in conjunction with an authenticator method they had registered earlier.
Upon gaining initial access, threat actors prioritize establishing persistent access. They achieve this by registering a phone number, an authenticator application, or a software one-time-password (OTP) token under their control. A simple password reset may not be sufficient to evict these attackers if active sessions, refresh tokens, or rogue authentication methods remain in place. Security teams must therefore investigate any suspicious sign-ins in conjunction with newly registered authentication factors.
Organizations have previously encountered Entra passkey enrollment attacks that leverage phone impersonation. Employees should always verify unexpected helpdesk requests through a known, official internal channel, never relying on a number or link provided by the caller. Establishing a verified reporting route for authentication requests can effectively neutralize such attacks before access is granted.
From Account Access to Cloud Collection
Once persistence is established, attackers leverage Microsoft Graph to enumerate the compromised user’s accessible resources. This includes a thorough discovery of users
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.