Passkey-themed phishing attacks lead to Microsoft 365 data theft

Published September 11, 2026

Attackers send fake Microsoft passkey and single sign-on emails to trick corporate users into handing over their Microsoft 365 login details. Once they get in, they steal company emails, files, and other sensitive data from Microsoft 365 services.

Report priority
High
Victim
Microsoft

What is known

  • Attackers send fake emails that look like they come from Microsoft.
  • These emails trick users into clicking a link that asks for their Microsoft 365 login details, pretending it's a passkey or single sign-on verification.
  • Once the user enters their credentials, the attackers use those details to log into their Microsoft 365 account and steal data.

What to do

If you work for a company that uses Microsoft 365 and recently got an email about verifying your passkey or single sign-on, do not click any links in it. If you already clicked a link and entered your login details, change your Microsoft 365 password immediately and monitor your account for unauthorized activity.

Change your Microsoft 365 password right away if you entered your login details after clicking a suspicious link. Enable two-factor authentication in your Microsoft account settings to add an extra layer of security. Watch for unusual activity in your emails and files, such as messages you didn't send or files you don't recognize. If you notice anything suspicious, report it to your IT department or Microsoft support.

Reported details

Attackers send an email with the subject 'Your Microsoft Passkey Verification Required' to a corporate employee. The email contains a fake Microsoft login page that looks real. When the employee enters their Microsoft 365 credentials, the attackers capture them and use them to access the employee's Microsoft 365 account, stealing emails and files.

Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.