Science and Technology

Hackers Are Using Passkeys as Bait to Steal Microsoft 365 Accounts

September 12, 2026 JauntyM 0
Hackers Are Using Passkeys as Bait to Steal Microsoft 365 Accounts

Hackers are now using passkeys as bait in phishing attacks targeting Microsoft 365 users, taking advantage of a security feature that many companies are actively encouraging employees to adopt.

The attack starts with a familiar trick: pretending to be IT support.

Attackers contact employees and claim that they need to set up, update or verify a passkey for their Microsoft 365 account. The victim is then directed to what appears to be a legitimate Microsoft login or authentication page.

However, the page is controlled by the attackers.

A Security Feature Becomes the Bait

Passkeys are designed to provide stronger protection against traditional phishing attacks by replacing passwords with cryptographic authentication tied to a trusted device or credential.

In this case, though, attackers aren’t necessarily trying to break the passkey technology itself. Instead, they’re using the idea of passkey enrollment or an account security update to convince victims to follow fraudulent instructions.

The fake Microsoft page is designed to look convincing enough that an employee may believe they are completing a legitimate request from their company’s IT department.

If the attack succeeds and the criminals gain access to the Microsoft 365 account, they can potentially establish another authentication method under their control to maintain access.

What Happens After an Account Is Compromised?

A compromised Microsoft 365 account can contain considerably more than email.

Depending on the employee’s permissions, attackers may be able to search through Outlook emails, SharePoint sites and OneDrive files looking for confidential information.

That could include internal documents, customer information, invoices, contracts, financial records or other sensitive company data.

Persistent access can make the situation even worse. If attackers successfully register their own authentication method, simply changing the employee’s password may not necessarily be enough to completely remove them.

Employees Should Be Careful With Passkey Requests

The campaign is another reminder that even stronger authentication technologies can’t eliminate social engineering.

Employees should be suspicious of unexpected messages asking them to register, reset or update authentication methods, particularly when those messages contain links.

Instead of following the supplied link, users should access Microsoft 365 through their organization’s normal login process or contact their IT department directly to confirm the request.

Companies should also monitor authentication-method changes and investigate unusual passkey or MFA registrations, particularly following suspicious login activity.

Passkeys can significantly improve account security, but attackers will continue looking for ways to target the person using the technology rather than the technology itself.

Share
← Previous Lenovo Yoga Slim 7x with Snapdragon X2 Elite: Future-Proof Power Just Got Affordable!
Next → AI Voice Service Ordered to Pay miHoYo $112,000 for Copying Genshin Impact Characters

Leave a Comment