Passkey Lure Used to Hijack M365 Accounts

CSO Online · Medium sophistication
Last updated September 11, 2026

Microsoft reports an active campaign where attackers pose as IT helpdesk staff and pressure employees to “update or enroll” passkeys, MFA, or SSO. Victims are pushed to either a fake Microsoft sign-in page (AiTM phishing) or a real Microsoft device-code flow, resulting in attackers gaining persistent access to Microsoft 365 accounts and data.

Key findings

  • Attackers impersonate IT helpdesk staff and use “passkey” updates as the lure.
  • Victims are routed to either adversary-in-the-middle (AiTM) phishing pages (to capture credentials/session tokens) or Microsoft device-code flows (to authorize an attacker-controlled client).
  • After compromise, attackers register their own MFA/authentication methods (phone, authenticator apps, software OTP) to maintain persistent access.
  • Attackers enumerate the tenant using Microsoft Graph and then access SharePoint/OneDrive files and Exchange Online email at a controlled pace to blend in.
  • Attackers sometimes send passkey-themed messages from already-compromised accounts via Microsoft Teams to appear as a trusted colleague.

Who’s being targeted

  • Commonly targeted roles: All employees, IT helpdesk, Identity and access management (IAM) team, Microsoft 365 administrators, Security operations (SOC).
  • Affected industries: Any organization using Microsoft 365.
  • Attack channels: vishing, website, teams.
  • Impersonated: Organization IT helpdesk, Trusted colleague (via compromised Teams account).

Awareness takeaways

  • Treat urgent “passkey/MFA/SSO update” requests as suspicious and verify through official IT channels before clicking links or following instructions.
  • Never enter a device code unless you personally initiated the login on your own device; device-code prompts can authorize attackers.
  • Be cautious of passkey-themed requests arriving via Teams, even if they appear to come from a colleague, because attackers may be using compromised internal accounts.
  • If an account is compromised, attackers may add their own MFA methods for persistence; new MFA/authenticator registrations should be treated as a major warning sign.

Red flags to watch for

  • Unsolicited urgent request tied to “avoid disruption” pressure
  • Link leads to a lookalike Microsoft sign-in page
  • Request comes to a personal mobile number rather than official IT channels
  • Helpdesk asks user to enter a device code they did not request
  • User is told it’s urgent and must be done immediately
  • The flow authorizes a client the user did not initiate
  • Unexpected security/process change request delivered via chat
  • Colleague is relaying an IT action instead of directing to official IT portal/process
  • Pressure/urgency language about outages or disruption
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a call on your personal phone: “Hi, this is the IT helpdesk, you must update your passkey or MFA right now to avoid disruption.” They send you a link that opens what looks exactly like a Microsoft sign-in page, or they say, “Type this code into Microsoft to finish your passkey update.” Either way, they’re hijacking your Microsoft 365 session. Once you sign in or enter that device code, they add their own MFA methods, then quietly search your Microsoft 365, SharePoint, OneDrive, email, at a slow pace so it looks normal. You might even get a similar passkey message in Teams from a coworker they already compromised. Your move: any urgent passkey, MFA, or SSO update request, phone, text, email, or Teams, hang up, ignore the link, and contact IT through our official helpdesk channel to confirm before you do anything.

Similar attacks

BlackFile Crew Vishing Hits PE and Finance Firms

BlackFile Crew Vishing Hits PE and Finance Firms

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike…

August 12, 2026
Fake IT Calls Steal Microsoft 365 Access

Fake IT Calls Steal Microsoft 365 Access

Microsoft reports a real-world campaign where attackers call or text employees’ personal phones while posing as internal IT. Victims are pushed to “update” passkeys/MFA/SSO and click a link to a fake Microsoft sign-in page, letting attackers get into Microsoft 365 and quietly pull email and files…

September 10, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
Vishing and Device-Code Tricks Drive Cloud Takeovers

Vishing and Device-Code Tricks Drive Cloud Takeovers

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers…

August 6, 2026
UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 is running real-world voice phishing (vishing) campaigns where callers impersonate IT help desk staff and create urgency around “mandatory” security changes. Victims are pushed to spoofed login pages that capture passwords and MFA codes, enabling attackers to access and steal data from SaaS…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026