
Attackers use passkey-themed scams to hijack Microsoft 365 accounts
Attackers are using passkey-themed social engineering to trick employees into giving them access to their Microsoft accounts.
Microsoft Security Research said it has been tracking active cloud intrusions since May in which attackers impersonated IT helpdesk staff, told employees they needed to update or enroll a passkey, and then took them to adversary-in-the-middle (AiTM) phishing pages or Microsoft device-code authentication flows.
The campaign ultimately gave attackers access to compromised cloud identities, allowing them to register their own authentication methods, map the victim’s Microsoft 365 environment, and access cloud-hosted files and emails.
“The passkey in this campaign is the ...