Passkey Social Engineering Attacks Breach Enterprise Cloud Data
Attackers send fake Microsoft passkey setup emails to trick enterprise users into giving up their cloud account credentials. This lets them hijack company email, files, and apps.
- Report priority
- Medium
How it works
- Attackers send fake Microsoft passkey setup emails to enterprise users.
- The emails look like official Microsoft notifications but trick users into clicking a malicious link.
- That link opens a fake Microsoft page asking for their cloud account password.
- Once the attacker gets the password, they can log in as the user and access their company email, files, and apps.
What to do
If you use Microsoft cloud services like Outlook, OneDrive, or Teams for work and received a suspicious email asking you to set up or verify a passkey, check your email for any unexpected messages about passkey setup or account security. If you clicked a link in such an email, change your password immediately via your company's IT support or Microsoft's official account recovery page.
If you clicked a link in a suspicious passkey email, go to your company's IT support or Microsoft's official account recovery page to reset your password. If you didn't click anything, report the email to your IT team or Microsoft's security team. Microsoft has not yet released a fix for this scam, so users must stay vigilant and avoid clicking unsolicited passkey links.
Technical details
An attacker sends an email to a company employee with the subject 'Your Microsoft Passkey Setup is Ready.' The email body says 'Complete your passkey setup to secure your account' and includes a link to a fake Microsoft page. When the employee clicks the link, they are asked to enter their Microsoft account password. The attacker captures the password and uses it to log into the employee's company account.
Microsoft warned of passkey social engineering attacks hitting tenants. Learn how passkey social engineering targets enterprise cloud identities.