Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issuesVolume 342, Issue 2IT Vendor NewsMicrosoft

Passkey-Themed Social Engineering Leads to Identity and Cloud Compromise

Microsoft, Wednesday, September 9th, 2026

Since May 2026 attackers have used passkey and SSO pretexts by phone and SMS to drive victims to phishing sites.

Microsoft researchers document a campaign running since May 2026 in which attackers use passkey or SSO enrolment pretexts, delivered by phone call and SMS, to direct victims to phishing sites.

After credential compromise the actors establish MFA persistence, run extensive Microsoft Graph reconnaissance, and extract data from SharePoint, OneDrive and email through REST APIs, with collection automated and routed through proxy infrastructure.

The pretext works because passkey rollouts are unfamiliar to users, which argues for publishing exactly what a legitimate enrolment looks like before attackers define it.

more →  ·  More from Microsoft →