Fake Passkey Updates Used to Hijack M365 Accounts

Biometric Update · Medium sophistication
Last updated September 21, 2026

Microsoft says attackers have been compromising Microsoft 365 cloud accounts by posing as internal IT staff and pressuring employees to “update” passkeys or sign-in settings. Victims are directed to lookalike sign-in pages or tricked into authorizing attacker access via device-code sign-in, after which attackers add their own authentication methods and steal data from SharePoint, OneDrive, and sometimes Exchange Online email.

How the attack worked

Attackers posed as internal IT helpdesk staff and reached out to employees directly on their personal phones, either by call or text. The pretext centered on a supposed need to update a passkey, multifactor authentication method, or single sign-on setting, framed with urgency: employees were warned they could lose access if they did not act. This outreach method is notable because it bypasses monitored corporate channels, meaning organizations may have little visibility into the first point of contact.

Once an employee engaged, they were directed to a sign-in page designed to look like a legitimate Microsoft login screen. In some cases, the attackers included the organization's name in the web address to increase the appearance of legitimacy. Requests were also sometimes relayed through an already compromised employee's Teams account, adding a layer of apparent trust since the message came from a colleague.

Why it succeeded

Two separate technical paths allowed account takeover. In one, an attacker-controlled site relayed the sign-in attempt to Microsoft and captured both credentials and a session token after the employee completed an MFA check that was not phishing-resistant. In another, the employee entered a device code on Microsoft's real authentication page, and that action authorized an attacker-controlled client to receive a token. Both methods exploit trust in familiar-looking authentication steps rather than relying on stolen passwords alone.

After gaining access, attackers added authentication methods they controlled, such as a phone number, authenticator app, or software one-time password. This gave them a durable way to satisfy future login challenges even if the original compromise was detected.

What to watch for

  • Unexpected calls or texts to a personal phone claiming to be from IT
  • Urgent language warning of lost access unless settings are updated immediately
  • Sign-in links that resemble Microsoft's login pages, even ones containing the organization's name
  • Sign-in setting requests arriving through Teams chat rather than official IT channels
  • Device code prompts appearing without the employee having initiated the sign-in themselves

Building resistance

Employees should verify any unexpected passkey, MFA, or SSO update request through a known, trusted IT channel rather than the number or link provided in the message. Organizations should consider requiring phishing-resistant MFA and restricting who can register new authentication methods, since attackers rely on adding their own methods to maintain access. Monitoring for new authentication method registrations and unusual device-code approvals can also help catch compromise attempts before attackers reach SharePoint, OneDrive, or Exchange Online data.

Key findings

  • Attackers posed as IT/helpdesk staff and used “passkey update” or other sign-in setting changes as the pretext.
  • Initial outreach was via call or text to an employee’s personal phone, increasing the chance the organization had limited visibility of the first contact.
  • Victims were sent to lookalike Microsoft sign-in pages; in some cases the org name was included in the URL to increase trust.
  • Microsoft observed multiple paths to takeover, including capturing credentials/session tokens after a non-phishing-resistant MFA step, and abusing device-code sign-in to authorize an attacker-controlled client.
  • After access, attackers added authentication methods they controlled (phone number, authenticator app, or software OTP) to make future logins easier.
  • Post-compromise activity included searching cloud resources and downloading data from SharePoint/OneDrive, and sometimes collecting email from Exchange Online for hours or days.

Who’s being targeted

  • Commonly targeted roles: All employees, IT helpdesk/service desk, Identity & access management (IAM) admins, Microsoft 365 administrators, Security operations (SOC).
  • Affected industries: Any organization using Microsoft 365 (cross-industry).
  • Attack channels: vishing, website, smishing, teams.
  • Impersonated: Internal IT helpdesk staff, Internal IT/helpdesk (via text message), Coworker/internal Teams account (compromised) and/or IT helpdesk.

Red flags to watch for

  • Unexpected IT outreach to a personal phone
  • Urgency/threat of losing access unless action is taken immediately
  • Link goes to a lookalike sign-in page (possibly with the org name embedded in the web address)
  • Request comes via personal phone outside normal IT channels
  • Mobile browsing reduces ability to verify URL and security indicators
  • Completing MFA on a page reached from an unsolicited text
  • Security/account-update requests arriving via Teams chat instead of official IT ticketing/email
  • Message comes from a colleague account but tone/behavior is unusual
  • Includes a link to a sign-in page that is only “similar” to Microsoft’s legitimate screens
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers trick employees into compromising their Microsoft 365 accounts?

Attackers called or texted employees' personal phones posing as IT helpdesk staff, warning they would lose access unless they updated a passkey, MFA, or SSO setting, then directed them to lookalike Microsoft sign-in pages.

What happened after attackers gained access to an account?

Attackers added their own authentication methods, such as a phone number, authenticator app, or software OTP, to maintain access, then searched and downloaded data from SharePoint, OneDrive, and sometimes Exchange Online email.

What is device-code phishing and why is it dangerous here?

In one case an employee entered a device code on Microsoft's real authentication page, and that step authorized an attacker-controlled client to receive a token, giving attackers access without needing to steal a password directly.

What can organizations do to reduce risk from these attacks?

Microsoft recommends requiring phishing-resistant MFA and restricting the registration of new authentication methods, along with training employees to verify unexpected sign-in setting requests through a trusted channel.

Read the video transcript

You get a text on your personal phone: “IT Helpdesk: update your Microsoft passkey now or you’ll lose access.” They say it’s a passkey or MFA update, and send you to a Microsoft login page that even has your company name in the web address. You sign in and even complete MFA, but behind the scenes they grab your session and add their own phone or authenticator, then quietly pull data from SharePoint, OneDrive, maybe your email for days. If anyone pushes a passkey or MFA update to your personal phone, don’t tap the link, contact IT through your usual channel and ask, “Did you really send this?”

Similar attacks

Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Passkey Helpdesk Scam Hijacks Microsoft Accounts

Passkey Helpdesk Scam Hijacks Microsoft Accounts

Microsoft described two real-world campaigns: an invoice fraud blast impersonating executives to trick finance teams into ACH payments, and a passkey-themed helpdesk scam that steals or bypasses authentication to take over Microsoft cloud accounts. In the second campaign, victims are called or…

September 13, 2026
Fake IT Calls Steal Microsoft 365 Access

Fake IT Calls Steal Microsoft 365 Access

Microsoft reports a real-world campaign where attackers call or text employees’ personal phones while posing as internal IT. Victims are pushed to “update” passkeys/MFA/SSO and click a link to a fake Microsoft sign-in page, letting attackers get into Microsoft 365 and quietly pull email and files…

September 10, 2026
Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
AI “Apple Support” Calls Steal iPhone Passcodes

AI “Apple Support” Calls Steal iPhone Passcodes

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a…

August 26, 2026