Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: passkey-phishing (1 article)Clear

Passkey-themed phishing hijacks Microsoft 365 accounts to slowly steal cloud data

Microsoft warned that extortion groups including ShinyHunters are running passkey and single-sign-on-themed phishing to break into Microsoft 365 accounts. Attackers impersonate the IT help desk by call, text, or Teams message, urging employees to urgently update a passkey or MFA setting, then send them to fake login pages. The passkey angle is only a lure: the real goal is to capture credentials and session tokens through an adversary-in-the-middle site or a device-code approval that bypasses MFA. Once in, they register their own authentication method for persistence, so a password reset alone will not evict them, then quietly exfiltrate under a thousand files an hour to blend in, spreading through connected single-sign-on services.

Check
Deploy phishing-resistant MFA and require managed devices for sensitive cloud resources, disable device-code authentication if unused, and tell staff to verify urgent passkey or MFA requests through a known internal channel.
Affected
Microsoft 365 organizations whose staff can be socially engineered over passkey or MFA lures; attackers steal session tokens or device-code approvals to bypass MFA and add their own authentication methods.
Fix
Hunt for unusual sign-ins followed by new authentication-method registrations, Graph API reconnaissance, and slow SharePoint or email access; on compromise, revoke sessions and tokens, reset credentials, and remove attacker-added methods.