Microsoft Passkey scam steals accounts

Published July 8, 2026

Microsoft Passkey scams trick users into handing over their Microsoft 365 accounts. Attackers send fake emails and set up fake websites to steal login details and take over accounts.

Report priority
High
Involves
Microsoft Entra ID

What is known

Attackers send fake emails and set up fake websites that look like Microsoft's real Passkey setup pages to trick users into entering their Microsoft 365 credentials.

What to do

Check if you got an unexpected email about Microsoft Passkey updates or visited a website with 'passkey' in the URL.

Do not click links in suspicious emails. Always verify Microsoft's official updates via Microsoft's real website or your Microsoft 365 account settings.

Reported details

You get an email saying your Microsoft 365 account needs a Passkey update. It links to a fake website. When you enter your Microsoft 365 username and password, the attackers steal them and take over your account.

A phishing campaign impersonates Microsoft Entra Passkey enrollment to trick users into handing over credentials. Attackers register fake domains like and, then create subdomains mimicking Microsoft's login pages. Victims who enter their credentials on these spoofed sites enable account takeover, allowing attackers to escalate access and demand data extortion.

The attack relies on social engineering rather than a technical vulnerability in Microsoft's Passkey system. No CVE or software version details are provided.