Fraudulent Gov Email and Passkey Lures Hit Orgs

Check Point Research · Medium sophistication
Last updated September 14, 2026

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately, researchers observed a “passkey”-themed campaign using phone and text messages to drive employees to lookalike Microsoft 365 sign-in pages to take over accounts.

Key findings

  • Revolut reported data exposure after employees complied with fraudulent information requests that appeared to come from an email account in a legitimate government domain.
  • The Revolut exposure included highly sensitive KYC and financial data (identity documents, selfies, contact details, IBANs, statements, withdrawals, and transaction histories).
  • A passkey-themed social engineering campaign targeted Microsoft 365 accounts using phone and text lures to send employees to lookalike sign-in pages.
  • After compromising accounts, attackers registered their own authentication methods and accessed data in SharePoint, OneDrive, and Exchange.

Who’s being targeted

  • Commonly targeted roles: All employees, Compliance and Legal, Fraud/Risk teams, Customer Support, IT administrators, Executives.
  • Affected industries: Financial services / fintech, Any organization using Microsoft 365 (cross-industry), Government (referenced as impersonated/abused identity).
  • Attack channels: email, vishing, smishing, website.
  • Impersonated: A government agency (using a legitimate government-domain email account), Microsoft 365 sign-in / account security team (via lookalike sign-in pages).

Awareness takeaways

  • Treat any request for customer/KYC or employee data as high risk and verify it through a formal process (case/ticket + legal validation), even if the sender domain looks legitimate.
  • Train staff that phone/text messages can be used to drive phishing; employees should navigate to Microsoft 365 using known bookmarks/apps, not links.
  • Add monitoring and approvals for new authentication method registration to prevent attackers from “locking in” persistence after a phishing login.
  • Explain the business impact: account takeover can expose sensitive collaboration and email data (SharePoint/OneDrive/Exchange), not just the mailbox.

Red flags to watch for

  • Unusual or urgent request for large volumes of customer/KYC data
  • Request relies on email-only approval instead of a validated legal request process
  • Sender domain may be legitimate but the request is not verified via an independent channel
  • Phone/text directing you to sign in via a link instead of using your normal Microsoft 365 URL/app
  • Lookalike sign-in page (slight URL/domain differences)
  • Unexpected prompts to add or approve new authentication methods
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: a real government email address asks you for customer records. Revolut replied to one… and exposed full KYC and financial data. The trick? Two plays. One: a massive email-only ask for identity documents, selfies, IBANs, and full transaction histories, all waved through just because the address ended in .gov. Two: a passkey-themed call or text pushing you to a lookalike Microsoft 365 sign-in page to 'enable passkeys'. Here’s the nasty part: once someone signs in on that fake Microsoft 365 page, the attacker quietly registers their own authentication methods, then starts pulling data from SharePoint, OneDrive, and Exchange, way beyond just email. Your move: if someone asks for customer data or to 'verify passkeys' via email, call, or text, stop and use your normal route, our legal request process or your usual Microsoft 365 bookmark or app, never the link they send you.

Similar attacks

Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Passkey Helpdesk Scam Hijacks Microsoft Accounts

Passkey Helpdesk Scam Hijacks Microsoft Accounts

Microsoft described two real-world campaigns: an invoice fraud blast impersonating executives to trick finance teams into ACH payments, and a passkey-themed helpdesk scam that steals or bypasses authentication to take over Microsoft cloud accounts. In the second campaign, victims are called or…

September 13, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026