Passkey-themed social engineering leads to identity and cloud compromise
Attackers trick Microsoft 365 users into adding fake passkeys to their accounts, then steal their data. This lets them access emails, files, and cloud services without your password.
- Report priority
- High
What is known
- Attackers send fake passkey setup emails or prompts that look like Microsoft's real passkey system.
- When you click, they add a fake passkey to your Microsoft account.
- This lets them bypass your password and take over your emails, files, and cloud services.
- They then use your account to steal data or spread further.
What to do
Check if you clicked a passkey setup link from an unexpected email or website. Look for unfamiliar passkeys in your Microsoft account under Security settings. If you see a passkey you didn't add, go to your Microsoft account security settings and remove any passkeys you don't recognize. Also, watch for unusual activity like emails or files disappearing or new unknown logins.
Change your password immediately. Check your emails, OneDrive, and SharePoint for suspicious activity. If your account was hacked, report it to Microsoft's support and monitor for further unauthorized access. For businesses, review security logs for unusual sign-ins and revoke compromised sessions.
Reported details
An attacker sends an email pretending to be Microsoft, asking you to set up a passkey for extra security. When you click the link, it adds a fake passkey to your account. The attacker then logs in using that passkey and starts downloading your emails and files from OneDrive and SharePoint.
This threat involves a passkey-themed social engineering campaign targeting cloud accounts, where attackers impersonate IT support to trick victims into visiting fake authentication pages. The attack begins with a call or SMS to a user's personal number, claiming urgent passkey or SSO updates are required. Victims are directed to a spoofed Microsoft sign-in page, where attackers bypass MFA by adding unauthorized authentication methods to compromised accounts.
Once access is established, the attackers perform Microsoft Graph reconnaissance, download files from SharePoint and OneDrive, and collect emails via REST APIs, indicating data exfiltration. The campaign has been active since May 2026, with attackers using proxy infrastructure to evade detection. Organizations should monitor unusual sign-ins, revoke unauthorized sessions, and remove added authentication methods for affected accounts.