Passkey-Themed Phishing Hits Microsoft 365

eSecurity Planet · High sophistication
Last updated September 15, 2026

Microsoft warns of an active social engineering campaign where attackers pose as an IT help desk and pressure employees to “update” passkeys/MFA/SSO. Victims are sent to fake Microsoft sign-in pages or tricked into approving access via device-code login, enabling attackers to add their own MFA methods and quietly steal data from SharePoint, OneDrive, and Exchange.

How the attack worked

This campaign starts with a message, by email or SMS, that impersonates a corporate IT help desk. The pretext is simple: a passkey, multifactor authentication, or single sign-on setting supposedly needs to be updated right away or the employee will lose account access. That urgency pushes the target toward a link that leads either to a fake Microsoft sign-in page or into a device-code authentication flow.

Both paths are dangerous in different ways. The fake sign-in pages act as adversary-in-the-middle phishing sites, capturing not just a password but the active session token, which can bypass normal MFA checks. The device-code flow is arguably more deceptive because it uses Microsoft's real authentication page. The user believes they are approving a routine sign-in, but they are actually authorizing an attacker-controlled application to access their account.

Why it succeeded

The scenario works because it borrows legitimacy from two directions at once: a trusted internal source (IT) and a trusted external one (Microsoft's own login pages or device-code system). Employees are conditioned to respond quickly to IT requests, especially ones framed around losing account access. Once inside, attackers commonly register their own phone number or authenticator app as a new MFA method. That step is what makes the intrusion durable: a password reset alone will not remove attacker access unless the added authentication method is also revoked and sessions and tokens are invalidated.

What to watch for

  • Unsolicited messages, especially urgent ones, claiming a passkey, MFA, or SSO setting must be updated immediately
  • Sign-in links delivered by text message rather than through known internal channels
  • Prompts to authorize a device or app that you did not initiate yourself
  • Any unexpected MFA enrollment notification, which may indicate an attacker has added their own method

After initial access, attackers use Microsoft Graph to inventory users, groups, roles, applications, authentication methods, SharePoint sites, OneDrive files, and mailbox content. Data theft can be deliberately throttled to blend in with normal activity, and intrusions may persist for hours or multiple days before being noticed.

Building resistance

  • Verify any passkey, MFA, or SSO update request with IT through a known internal contact method rather than replying to the message or link directly
  • Use bookmarked or manually typed URLs to reach Microsoft sign-in pages instead of clicking links from email or SMS
  • Treat any device-code or app-authorization prompt you did not initiate as suspicious and report it immediately
  • If a suspicious login or approval is suspected, report it right away so unauthorized authentication methods can be removed and sessions and tokens revoked, since a single compromised identity can expose cloud files, email, and connected applications across an organization

Key findings

  • Attackers impersonate corporate IT help desks and claim passkey/MFA/SSO settings must be updated urgently to avoid losing access.
  • Victims are directed to fake Microsoft sign-in pages (including adversary-in-the-middle phishing) or pushed into device-code authentication flows.
  • After initial access, attackers add their own authentication methods (phone number/authenticator app) to maintain access even after password resets unless sessions/tokens and methods are revoked/removed.
  • Attackers use Microsoft Graph to inventory cloud resources (users, groups, roles, apps, auth methods, SharePoint/OneDrive, mailboxes).
  • Data theft can be intentionally throttled to blend in (e.g., fewer than 1,000 files/emails per hour) and intrusions may last hours to multiple days.
  • Microsoft attributed initial access to multiple threat actors, including Storm-3121 and Storm-3032, and linked activity to data theft and extortion.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, HR, IT helpdesk, Cloud/Identity administrators.
  • Affected industries: Any organization using Microsoft 365 (cross-industry).
  • Attack channels: email, smishing, website.
  • Impersonated: Corporate IT help desk, Corporate IT / Microsoft 365 support, Microsoft sign-in / device-code authentication.

Red flags to watch for

  • Urgent pressure to act immediately “to avoid losing access”
  • Login link leads to a lookalike Microsoft sign-in page
  • Unexpected authentication changes prompted by an unsolicited message
  • IT requests arriving via SMS with a login link
  • A link to a sign-in page you didn’t request
  • Message implies account access will be lost unless you act now
  • You are asked to authorize a device/app you are not setting up
  • Unexpected device-code prompts or approvals
  • Approval request does not match your current login activity
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the passkey phishing scam impersonate IT help desks?

Attackers pose as corporate IT and warn employees that a passkey, multifactor authentication, or single sign-on setting must be updated immediately or access will be lost, pushing them toward fake Microsoft sign-in pages or device-code authentication flows.

What happens after an attacker gains access to an account?

Attackers commonly register a phone number, authenticator app, or other MFA method they control, which can preserve access even after a password reset unless defenders remove the unauthorized methods and revoke active sessions and tokens.

Why is device-code phishing dangerous even though it uses Microsoft's real login page?

Device-code phishing can trick a user into authorizing an attacker-controlled client through Microsoft's legitimate authentication page, meaning the victim believes they are approving something normal while granting an attacker access.

What can attackers do once inside a Microsoft 365 environment?

They use Microsoft Graph to inventory users, groups, directory roles, applications, authentication methods, SharePoint sites, OneDrive files, and mailbox content, and can throttle data theft to fewer than 1,000 files or emails per hour to avoid detection.

Read the video transcript

You get an email from “IT Help Desk”: update your Microsoft 365 passkey now or you’ll lose access. You click their link and land on what looks exactly like a Microsoft login. But it’s an adversary-in-the-middle page, quietly stealing your password and session so they can add their own MFA and stay in your account. From there, they register their own phone or authenticator app, then quietly pull files and emails from SharePoint, OneDrive, and Exchange using normal-looking Microsoft Graph activity. If you ever get an urgent passkey, MFA, or SSO update request, don’t touch the link, contact our IT using our internal help desk or chat and ask, "Did you really send this?"

Similar attacks

Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
Phish Adds Passkey That Survives Reset

Phish Adds Passkey That Survives Reset

Researchers described iAuthFlow v2, a phishing toolkit that steals a live Google login session and then uses that access to enroll an attacker-controlled passkey. Because passkeys are separate login methods, the attacker can often get back into the account even after the victim changes their…

August 24, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
Trezor Users Hit by Phish via Brevo Breach

Trezor Users Hit by Phish via Brevo Breach

Attackers broke into Brevo, the email platform Trezor uses for newsletters, and sent a phishing “security warning” from Trezor’s real mailing system. The email claimed a serious hardware issue could expose wallet recovery seeds and pushed people to a malicious site/app that asked for a wallet…

September 14, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Passkey Helpdesk Scam Hijacks Microsoft Accounts

Passkey Helpdesk Scam Hijacks Microsoft Accounts

Microsoft described two real-world campaigns: an invoice fraud blast impersonating executives to trick finance teams into ACH payments, and a passkey-themed helpdesk scam that steals or bypasses authentication to take over Microsoft cloud accounts. In the second campaign, victims are called or…

September 13, 2026