Passkey “Update” Prompts Fuel New Microsoft Phish

TechRepublic Security · High sophistication
Last updated September 21, 2026

Microsoft says attackers are impersonating IT support and using “passkey/MFA/SSO update” requests to trick employees into authenticating attacker-controlled sessions. The campaigns use attacker-in-the-middle phishing sites or device-code logins to capture valid session tokens, then access Microsoft 365 data like SharePoint, OneDrive, and Exchange Online and add new authentication methods to stay in the account.

How the attack worked

Microsoft has tracked campaigns, active since May 2026, where attackers impersonate IT support and tell employees they need to update a passkey, MFA, or SSO setting. The message pushes the target toward one of two technical paths. In the first, an attacker-in-the-middle site sits between the victim and Microsoft's real login service, relaying a genuine sign-in while quietly capturing the authenticated session token issued during the process. In the second, device-code phishing, the attacker starts a legitimate Microsoft sign-in on their own device, receives a code, and convinces the victim to enter that code on Microsoft's real authentication page. Microsoft then issues the authentication token to the attacker's device rather than the victim's.

Why it succeeded

Both methods work because the victim is interacting with a real Microsoft sign-in flow at some point in the process, not an obviously fake page. The pretext, a routine-sounding security update, gives the request legitimacy and urgency at the same time. Microsoft has attributed this activity to multiple threat groups, including Storm-3121 and Storm-3032, and Google has tracked a similar pattern under the name UNC6671, indicating the technique is being used broadly rather than by a single actor. Attackers also research employees and org structure from public sources beforehand, and may use compromised accounts to reach victims through trusted channels like Microsoft Teams, which increases perceived legitimacy.

What to watch for

  • An unsolicited message telling you to update a passkey, MFA, or SSO setting
  • Pressure to click a provided link instead of using a known internal portal
  • A device code you're asked to enter that you did not request yourself
  • A login page reached through a message link where the address bar doesn't match the expected Microsoft domain
  • Re-authentication prompts that feel unnecessary given your recent activity

How to build resistance

After gaining access, Microsoft observed attackers performing reconnaissance, adding their own authentication methods to compromised accounts to maintain persistence, and accessing SharePoint, OneDrive, and Exchange Online data. Defenses should focus on the two points where the technique depends on human action:

  • Verify any passkey, MFA, or SSO update request through a known internal channel before acting, never through a link in the message itself
  • Train staff to never enter device codes or approve sign-ins they did not personally initiate
  • Tightly control who can add new authentication methods to an account and monitor for sudden changes
  • If compromise is suspected, revoke active sessions and tokens and remove unauthorized authentication methods promptly

Because the underlying sign-in pages are genuine, technical controls alone won't fully stop this pattern; employee awareness of what a legitimate IT request looks like remains a key control (see T1566.002 and T1656).

Key findings

  • Microsoft tracked campaigns since May 2026 where attackers impersonate IT staff and claim employees must update passkeys, MFA, or SSO settings.
  • Attackers use attacker-in-the-middle phishing to relay real Microsoft sign-ins and steal the authenticated session token.
  • Attackers also use device-code phishing by convincing victims to enter a code on Microsoft’s real login page, which approves the attacker’s device.
  • After compromise, attackers perform reconnaissance, add their own authentication methods for persistence, and access SharePoint/OneDrive/Exchange Online data.
  • Microsoft attributes activity to multiple threat groups, including Storm-3121 and Storm-3032; Google has tracked a similar pattern as UNC6671.
  • Attackers research employees and org structure from public sources and may abuse compromised accounts to message victims through trusted channels like Microsoft Teams.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, HR, IT helpdesk/service desk, Security/Identity team.
  • Affected industries: Any organization using Microsoft 365 (cross-industry).
  • Attack channels: email, website.
  • Impersonated: Internal IT support / helpdesk, Microsoft sign-in / security page (lookalike), IT support guiding a Microsoft device-code sign-in.

Red flags to watch for

  • Unsolicited request to change authentication settings
  • Pressure to use a provided link rather than internal portals
  • Unexpected re-authentication prompts tied to a “security update”
  • Login page reached via message link rather than known bookmark
  • Re-authentication request that feels unnecessary
  • Browser/address bar doesn’t match expected Microsoft login domain
  • You’re asked to type in a code you didn’t request
  • You’re “approving” a login for someone else’s device/session
  • Request arrives out of the blue as a ‘security update’
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How do attackers use fake passkey update requests to phish Microsoft accounts?

Attackers impersonate IT staff and tell employees they need to update a passkey, MFA, or SSO setting, then direct them to an attacker-in-the-middle site or a device-code login flow that captures a valid authenticated session token.

What is device-code phishing in this campaign?

The attacker starts a legitimate Microsoft sign-in on their own device, gets a code, and convinces the victim to enter that code on Microsoft's real authentication page, which causes Microsoft to issue the authentication token to the attacker's device.

What do attackers do after compromising an account?

Microsoft observed attackers performing reconnaissance, adding their own authentication methods to maintain persistence, and accessing SharePoint, OneDrive, and Exchange Online data.

How can organizations reduce risk from these fake authentication update prompts?

Verify any passkey, MFA, or SSO update request through a known internal channel rather than a link in a message, train staff to never approve sign-ins or enter device codes they did not initiate, and tightly control who can add new authentication methods.

Read the video transcript

You get a Teams or email from “IT Support”: update your passkey or you’ll lose Microsoft 365 access. This is a passkey scam Microsoft’s tracking from groups like Storm-3121. You click their link, land on an Attacker-in-the-Middle phishing page that looks like Microsoft sign-in, and they silently steal your session token. Or they send you a code and say, 'Enter this on Microsoft to update MFA.' You type it into the real page, but you’ve actually approved their device, giving them access to SharePoint, OneDrive, and Exchange Online. Here’s the move: any passkey, MFA, or SSO update request, email, Teams, whatever, ignore the link and contact IT using a known internal channel you pick, not the one in the message.

Similar attacks

Fake IT Calls Steal Microsoft 365 Access

Fake IT Calls Steal Microsoft 365 Access

Microsoft reports a real-world campaign where attackers call or text employees’ personal phones while posing as internal IT. Victims are pushed to “update” passkeys/MFA/SSO and click a link to a fake Microsoft sign-in page, letting attackers get into Microsoft 365 and quietly pull email and files…

September 10, 2026
Browser Trust Scams: Fake Updates, BitB, ClickFix

Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run…

August 26, 2026
Voicemail Phish Steals Microsoft 365 Sessions

Voicemail Phish Steals Microsoft 365 Sessions

Researchers describe an active, widespread email campaign that tricks employees with voicemail-themed messages and steals Microsoft 365 login sessions (including MFA codes). After taking over accounts, attackers quietly search and collect payroll/HR/finance emails and identify people involved in…

August 7, 2026
Vishing and Device-Code Tricks Drive Cloud Takeovers

Vishing and Device-Code Tricks Drive Cloud Takeovers

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers…

August 6, 2026
Device-Code Phish Bypasses MFA via Real Microsoft Login

Device-Code Phish Bypasses MFA via Real Microsoft Login

Attackers abused Microsoft’s OAuth “device code” sign-in so victims completed a real Microsoft login and MFA, but the resulting session tokens were issued to the attacker. In a documented Microsoft 365 takeover, the attacker used a believable partner-law-firm email thread and a Google Sites lure…

July 22, 2026
RingCentral Breach Fuels Spoofed M365 Phish Risk

RingCentral Breach Fuels Spoofed M365 Phish Risk

Have I Been Pwned says the RingCentral incident exposed 1.6 million email addresses plus names, phone numbers, and physical addresses, which can make targeted phishing more convincing. Separately, researchers described spoofed RingCentral emails that bypassed defenses due to allowlisting and led…

August 14, 2026