Fake IT Calls Steal Microsoft 365 Access

Help Net Security · High sophistication
Last updated September 10, 2026

Microsoft reports a real-world campaign where attackers call or text employees’ personal phones while posing as internal IT. Victims are pushed to “update” passkeys/MFA/SSO and click a link to a fake Microsoft sign-in page, letting attackers get into Microsoft 365 and quietly pull email and files for days or weeks.

Key findings

  • Attackers contact employees on personal phones (calls/texts) while impersonating internal IT staff to trigger urgent “passkey/MFA/SSO updates.”
  • Victims receive a link to a fake Microsoft sign-in page; the passkey story is used as a pretext to perform AiTM phishing or device-code authentication flows.
  • Attackers may reuse a compromised employee account to send the same lure to coworkers over Microsoft Teams.
  • After initial access, attackers add their own MFA methods (phone number/authenticator/OTP) to maintain long-term access (“durable persistence”).
  • They use Microsoft Graph API to enumerate users, groups, roles, auth methods, and apps, then access mail/files across SharePoint, OneDrive, and Exchange.
  • Data theft is intentionally throttled (e.g., staying below ~1,000 items/hour) to blend into normal usage.
  • Microsoft attributes initial access activity to multiple actors including Storm-3121 and Storm-3032.

Who’s being targeted

  • Commonly targeted roles: All employees, IT helpdesk/service desk, Microsoft 365 administrators, Security operations / incident response.
  • Affected industries: Cross-industry (any organization using Microsoft 365).
  • Attack channels: vishing, smishing, website, teams.
  • Impersonated: Internal IT staff / Helpdesk, A known coworker (from their compromised Microsoft Teams account).

Awareness takeaways

  • Treat urgent passkey/MFA/SSO “update” requests via personal phone as suspicious; verify via official IT channels before clicking anything.
  • Be wary of links to “Microsoft sign-in” pages sent by text/Teams, use a known bookmark or type the official address instead.
  • Don’t assume passkey-themed messages are safe; attackers can use “passkeys” as a cover to steal sign-in sessions or approvals.
  • Train teams to recognize that compromised coworker accounts can be used to spread lures internally (e.g., via Teams).

Red flags to watch for

  • Urgency and pressure to act immediately to avoid “disruption”
  • Link opens a lookalike Microsoft sign-in page
  • Contact comes via personal phone number outside normal IT channels
  • Unexpected “passkey update” message from a coworker
  • Link/URL looks only slightly off (org name used as a subdomain)
  • Request is inconsistent with normal IT processes (no ticket, no verified notice)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re at home, personal phone rings: “Hi, this is IT. Your passkey and MFA must be updated right now or your access breaks.” They text you a link. You tap it, and a perfect-looking Microsoft sign-in page pops up. But it’s a fake, built just to steal your Microsoft 365 login and MFA approvals. Here’s the twist: once you sign in, they add their own MFA, then quietly pull mail and files from SharePoint, OneDrive, and Exchange for days, sometimes even messaging coworkers on Teams with the same fake passkey link. If anyone pushes a passkey or MFA update to your personal phone, don’t tap the link, hang up, ignore the text, and contact IT using our official helpdesk channel instead.

Similar attacks

Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
Vishing and Device-Code Tricks Drive Cloud Takeovers

Vishing and Device-Code Tricks Drive Cloud Takeovers

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers…

August 6, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Voicemail Phish Steals Microsoft 365 Sessions

Voicemail Phish Steals Microsoft 365 Sessions

Researchers describe an active, widespread email campaign that tricks employees with voicemail-themed messages and steals Microsoft 365 login sessions (including MFA codes). After taking over accounts, attackers quietly search and collect payroll/HR/finance emails and identify people involved in…

August 7, 2026