<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Hackers Are Using Fake Passkey Requests to Break Into Microsoft 365 Accounts

Phishing attack bypasses MFA, infiltrates Microsoft 365 accounts, and extracts data stealthily. Learn how to protect your organization.
Content Team

A sophisticated phishing campaign has been hijacking Microsoft 365 accounts since May 2026 — and it can defeat MFA protections entirely. Attackers pose as IT support via phone or text, claiming a passkey or sign-on setting needs attention, then direct victims to fake Microsoft login pages. From there, they capture credentials and session tokens, or trick users into approving device-code sign-ins that hand over cloud access.

Once inside, attackers quietly map the organization using Microsoft Graph, then download files from SharePoint, OneDrive, and Exchange — often staying below 1 000 items per hour to avoid detection. A password reset alone won't remove them if rogue authentication methods remain active. Microsoft recommends revoking sessions, removing unauthorized MFA methods, and requiring phishing-resistant authentication going forward.

Source: Cyber Security News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo