Microsoft 365 Passkey Phishing Turns Login Into a Cloud Breach

Microsoft warns that passkey-themed phishing is hijacking Microsoft 365 accounts, adding rogue MFA methods, and slowly stealing business cloud data.

Written By
KJ
Kezia Jungco
Sep 14, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Microsoft is warning of an ongoing social engineering campaign that uses passkey enrollment as a lure to compromise corporate accounts and steal data from Microsoft 365 services.

The attacks, observed since May 2026, begin with threat actors impersonating IT help desks and directing employees to fake Microsoft sign-in pages or device-code authentication flows. After gaining access, attackers add their own authentication methods, use Microsoft Graph to map cloud resources, and collect data from SharePoint, OneDrive, and Exchange. The campaign abuses passkeys as a social engineering lure rather than exploiting the technology itself.

How the passkey phishing attack works

The campaign often starts with research on a target company and its employees. Attackers then impersonate corporate IT and warn that a passkey, multifactor authentication, or single sign-on setting must be updated immediately to avoid losing access.

Victims may receive links by SMS to pages designed to look like Microsoft sign-in screens. BleepingComputer reported that the attackers use those lures to push victims into adversary-in-the-middle phishing or device-code authentication rather than actually enrolling a passkey.

AiTM pages can capture credentials and session tokens, while device-code phishing can trick a user into authorizing an attacker-controlled client through Microsoft’s legitimate authentication page.

Attackers turn one account into a cloud map

After gaining access, the attackers commonly register a phone number, authenticator app, or other MFA method they control. That can preserve access even after a password reset unless defenders remove unauthorized authentication methods and revoke the victim’s active sessions and tokens.

Microsoft said the attackers then use Microsoft Graph to inventory users, groups, directory roles, applications, authentication methods, SharePoint sites, OneDrive files, and mailbox content. Individual Graph requests may look normal in an enterprise environment, making the sequence of activity more important than any single API call.

Data theft can also be deliberately slow. Microsoft observed intrusions lasting from several hours to multiple days. According to BleepingComputer, Microsoft observed attackers accessing fewer than 1,000 files or emails per hour in some cases, helping the activity blend into legitimate cloud traffic.

Advertisement

The campaign is tied to an extortion ecosystem

The Hacker News reported that Microsoft attributed the initial-access activity to multiple threat actors, including Storm-3121 and Storm-3032. Microsoft linked compromises involving these groups to a broader ecosystem of data theft and extortion activity.

For defenders, that raises the stakes beyond a single compromised mailbox. One stolen identity can become a route into cloud files, email, business applications, and other resources connected through SSO.

What defenders should do now

Microsoft recommends treating the intrusion as a connected identity-to-cloud sequence instead of looking for one suspicious event. Security teams should:

  • Review unusual sign-ins and authentication changes: Check for newly registered MFA methods, devices, and application authorizations. After validating the user, remove unauthorized methods and revoke active sessions and tokens.
  • Correlate identity and cloud activity: Look for Microsoft Graph reconnaissance followed by unusual SharePoint, OneDrive, Exchange mailbox, or file-download activity.
  • Tighten authentication and recovery controls: Enforce phishing-resistant MFA and Conditional Access, restrict unmanaged-device downloads, and verify identities before help-desk credential or MFA resets.

The campaign shows why stronger authentication cannot be the only line of defense. Passkeys can make credential phishing harder, but security teams also need controls around enrollment, account recovery, help-desk requests, session revocation, and the cloud activity that follows a successful takeover.

Also read: Learn how BigBear 2.0 bypassed Microsoft 365 MFA at 258 organizations by stealing session cookies, and what security teams can do to respond.

KJ

Kezia Jungco is a technology writer and researcher specializing in artificial intelligence, data analytics, CRM software, cloud infrastructure, cybersecurity, and emerging business technologies. With more than five years of experience evaluating software platforms and technology solutions, she helps business leaders understand the tools and trends shaping the future of work. Kezia has extensive hands-on experience testing and analyzing generative AI platforms, chatbots, natural language processing (NLP) tools, CRM systems, and business software. Her work focuses on translating complex technologies into practical insights that help organizations make informed decisions about technology adoption, operational efficiency, and digital transformation. As a staff writer for TechnologyAdvice, Kezia covers AI innovation, business applications of machine learning, data-driven technologies, cloud computing, cybersecurity, and sales technology. Her background in journalism, research, and education enables her to combine rigorous analysis with clear, accessible reporting for both enterprise and consumer audiences. Kezia holds a bachelor's degree in Development Communication with a major in Development Journalism from the University of the Philippines Los Baños. She has also completed professional training in artificial intelligence, data privacy, and information security. Her work has been featured in TechnologyAdvice, TechRepublic, eWeek, Datamation, and Selling Signals, where she helps readers navigate a rapidly evolving technology landscape with practical, research-driven guidance.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.