Passkey-Themed Social Engineering Leads to Identity and Cloud Compromise
Microsoft, Wednesday, September 9th, 2026
Since May 2026 attackers have used passkey and SSO pretexts by phone and SMS to drive victims to phishing sites.
Microsoft researchers document a campaign running since May 2026 in which attackers use passkey or SSO enrolment pretexts, delivered by phone call and SMS, to direct victims to phishing sites.
After credential compromise the actors establish MFA persistence, run extensive Microsoft Graph reconnaissance, and extract data from SharePoint, OneDrive and email through REST APIs, with collection automated and routed through proxy infrastructure.
The pretext works because passkey rollouts are unfamiliar to users, which argues for publishing exactly what a legitimate enrolment looks like before attackers define it.