Passkey Helpdesk Scam Hijacks Microsoft Accounts

The Hacker News · High sophistication
Last updated September 14, 2026

Microsoft described two real-world campaigns: an invoice fraud blast impersonating executives to trick finance teams into ACH payments, and a passkey-themed helpdesk scam that steals or bypasses authentication to take over Microsoft cloud accounts. In the second campaign, victims are called or texted and then pushed to fake Microsoft login pages, after which attackers add their own MFA methods and quickly download email and files from SharePoint/OneDrive.

How the attack worked

Microsoft described two distinct real-world campaigns. The first targeted Accounts Payable and Finance staff with executive impersonation emails demanding ACH transfers for a fake ServiceNow annual subscription invoice, using trusted infrastructure, fabricated invoices, and even forged supporting email threads to appear legitimate. The second campaign used passkey, MFA, and SSO themes to hijack Microsoft accounts directly. Attackers called or texted a victim's personal phone, posed as the internal IT help desk, and pushed an urgent need to update authentication settings. Victims were then redirected via SMS to counterfeit Microsoft sign-in pages, where adversary-in-the-middle or device-code authentication flows let attackers capture session access and take over the account. In some cases, already compromised accounts were used to send similar passkey-themed lures internally via Microsoft Teams.

Why it succeeded

Both campaigns relied on urgency and authority rather than technical exploits. The invoice scam borrowed real executive names and paired them with a plausible vendor renewal, giving finance staff a reason to act quickly outside normal procurement checks. The helpdesk scam exploited the fact that identity and access issues feel time sensitive: an employee told their passkey or MFA needs immediate attention is primed to comply without pausing to verify the source. Once attackers gained account control, they reinforced their access by adding their own MFA methods, making the takeover harder to notice or reverse quickly.

What to watch for

  • Unexpected calls or texts to a personal phone claiming to be IT help desk staff
  • Urgent requests to update passkeys, MFA, or SSO settings
  • Links that lead to sign-in pages resembling Microsoft's login but on unfamiliar domains
  • Invoice emails carrying an embedded 'approval' from an executive rather than following normal payment workflows
  • Attached invoices paired with supporting email threads that could be fabricated

How to build resistance

Employees should verify any passkey, MFA, or SSO change request through official IT channels before clicking a link or entering credentials, especially when the outreach arrives on a personal device. Finance teams should independently confirm payment requests tied to executive emails using known contacts and established procurement steps, rather than acting solely on an emailed 'approval.' Organizations can also reduce risk by training staff to recognize authentication-themed domains and by reinforcing that legitimate IT support rarely initiates urgent, unsolicited outreach about account security settings.

Key findings

  • Microsoft reported a campaign that sent "over a million scam emails" (Aug 3–5, 2026) impersonating CEOs to push Accounts Payable teams into making ACH payments for a fake "ServiceNow annual subscription."
  • The invoice fraud emails used "trusted infrastructure" plus "fabricated invoices" and even a "forged email thread" to appear legitimate, including real executive names in signatures.
  • A separate campaign used passkey/MFA/SSO-themed helpdesk pretexts: attackers "call or message a user's personal phone number" and then redirect targets via SMS to "counterfeit websites" mimicking Microsoft sign-in.
  • Attackers aimed to take over Microsoft accounts through "adversary-in-the-middle (AitM) or device-code authentication flows," then added attacker-controlled MFA methods for persistence and performed large-scale cloud data collection.
  • Microsoft linked initial access activity in the passkey campaign to threat actors including "Storm-3121" and "Storm-3032" (with overlap references to UNC6671 and other community names).

Who’s being targeted

  • Commonly targeted roles: Accounts Payable, Finance, All employees, Executives (for impersonation risk), IT help desk / Identity team.
  • Affected industries: IT services, Consumer goods, Real estate, Manufacturing, Enterprise organizations using Microsoft 365/Entra ID.
  • Attack channels: email, vishing, smishing, website, teams.
  • Impersonated: Company CEO (executive impersonation) using vendor branding (ServiceNow), Organization's IT help desk, Internal coworker/IT (using an already compromised account).

Red flags to watch for

  • Pressure to pay based on an "approval" embedded in the email rather than normal procurement process
  • Domain and sender branding slightly off (impersonation domains)
  • Attached invoice plus a "supporting" thread that can be fabricated
  • Unexpected IT helpdesk outreach to a personal phone number
  • Link leads to a lookalike Microsoft login site
  • Urgent language about avoiding immediate access loss
  • Unexpected passkey/SSO enrollment request via Teams
  • Sender is a real internal account but the request is out of normal process
  • Links/domains reference passkeys/SSO but are not official company or Microsoft domains
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the passkey helpdesk scam work?

Attackers call or text a user's personal phone claiming to be the organization's IT help desk, urging an urgent passkey, MFA, or SSO update. Victims are redirected via SMS to counterfeit Microsoft sign-in pages, where attackers use adversary-in-the-middle or device-code flows to take over the account.

What happens after an account is taken over?

According to the reporting, attackers add their own MFA methods to maintain persistence and then quickly collect email and files from SharePoint and OneDrive.

Is this related to the invoice fraud campaign?

They are two separate campaigns described in the same report. One uses passkey/MFA/SSO pretexts to hijack Microsoft accounts, while the other impersonates CEOs to push Accounts Payable teams into ACH payments for a fake ServiceNow subscription invoice.

What are the warning signs of the invoice fraud emails?

Red flags include a purported executive 'approval' embedded in the email, impersonation domains, fabricated invoices, and even forged supporting email threads meant to add legitimacy.

Read the video transcript

You get a call on your personal phone: “This is IT help desk, you need to update your Microsoft passkey now or you’ll lose access.” They text you a link that looks like Microsoft sign-in. You tap, see a familiar blue login page, enter your password, approve the prompt… and in the background, an adversary-in-the-middle flow hands your session to them. Now they add their own MFA method to your Microsoft account and quietly start downloading mail, SharePoint, and OneDrive files, using your session as if they were you. If anyone contacts your personal phone about passkeys, MFA, or SSO, don’t tap the link, hang up and contact our IT team through the official helpdesk channel you already use.

Similar attacks

Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
AI “Apple Support” Calls Steal iPhone Passcodes

AI “Apple Support” Calls Steal iPhone Passcodes

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a…

August 26, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026