Microsoft is warning of an ongoing social engineering campaign that uses passkey enrollment as a lure to compromise corporate accounts and steal data from Microsoft 365 services.
The attacks, observed since May 2026, begin with threat actors impersonating IT help desks and directing employees to fake Microsoft sign-in pages or device-code authentication flows. After gaining access, attackers add their own authentication methods, use Microsoft Graph to map cloud resources, and collect data from SharePoint, OneDrive, and Exchange. The campaign abuses passkeys as a social engineering lure rather than exploiting the technology itself.
How the passkey phishing attack works
The campaign often starts with research on a target company and its employees. Attackers then impersonate corporate IT and warn that a passkey, multifactor authentication, or single sign-on setting must be updated immediately to avoid losing access.
Victims may receive links by SMS to pages designed to look like Microsoft sign-in screens. BleepingComputer reported that the attackers use those lures to push victims into adversary-in-the-middle phishing or device-code authentication rather than actually enrolling a passkey.
AiTM pages can capture credentials and session tokens, while device-code phishing can trick a user into authorizing an attacker-controlled client through Microsoft’s legitimate authentication page.
Attackers turn one account into a cloud map
After gaining access, the attackers commonly register a phone number, authenticator app, or other MFA method they control. That can preserve access even after a password reset unless defenders remove unauthorized authentication methods and revoke the victim’s active sessions and tokens.
Microsoft said the attackers then use Microsoft Graph to inventory users, groups, directory roles, applications, authentication methods, SharePoint sites, OneDrive files, and mailbox content. Individual Graph requests may look normal in an enterprise environment, making the sequence of activity more important than any single API call.
Data theft can also be deliberately slow. Microsoft observed intrusions lasting from several hours to multiple days. According to BleepingComputer, Microsoft observed attackers accessing fewer than 1,000 files or emails per hour in some cases, helping the activity blend into legitimate cloud traffic.
The campaign is tied to an extortion ecosystem
The Hacker News reported that Microsoft attributed the initial-access activity to multiple threat actors, including Storm-3121 and Storm-3032. Microsoft linked compromises involving these groups to a broader ecosystem of data theft and extortion activity.
For defenders, that raises the stakes beyond a single compromised mailbox. One stolen identity can become a route into cloud files, email, business applications, and other resources connected through SSO.
What defenders should do now
Microsoft recommends treating the intrusion as a connected identity-to-cloud sequence instead of looking for one suspicious event. Security teams should:
- Review unusual sign-ins and authentication changes: Check for newly registered MFA methods, devices, and application authorizations. After validating the user, remove unauthorized methods and revoke active sessions and tokens.
- Correlate identity and cloud activity: Look for Microsoft Graph reconnaissance followed by unusual SharePoint, OneDrive, Exchange mailbox, or file-download activity.
- Tighten authentication and recovery controls: Enforce phishing-resistant MFA and Conditional Access, restrict unmanaged-device downloads, and verify identities before help-desk credential or MFA resets.
The campaign shows why stronger authentication cannot be the only line of defense. Passkeys can make credential phishing harder, but security teams also need controls around enrollment, account recovery, help-desk requests, session revocation, and the cloud activity that follows a successful takeover.
Also read: Learn how BigBear 2.0 bypassed Microsoft 365 MFA at 258 organizations by stealing session cookies, and what security teams can do to respond.





