Hackers Are Using Fake Passkey Requests to Break Into Microsoft 365 Accounts
Want more insights like this?
A sophisticated phishing campaign has been hijacking Microsoft 365 accounts since May 2026 — and it can defeat MFA protections entirely. Attackers pose as IT support via phone or text, claiming a passkey or sign-on setting needs attention, then direct victims to fake Microsoft login pages. From there, they capture credentials and session tokens, or trick users into approving device-code sign-ins that hand over cloud access.
Once inside, attackers quietly map the organization using Microsoft Graph, then download files from SharePoint, OneDrive, and Exchange — often staying below 1 000 items per hour to avoid detection. A password reset alone won't remove them if rogue authentication methods remain active. Microsoft recommends revoking sessions, removing unauthorized MFA methods, and requiring phishing-resistant authentication going forward.
Source: Cyber Security News