Researchers Warn: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers

In a sophisticated evolution of cyber-espionage, threat actors are leveraging the industry-wide transition toward passwordless authentication to deceive employees into compromising their own enterprise credentials. A widespread social engineering campaign, identified and analyzed by Microsoft’s threat intelligence teams, has been targeting organizational cloud environments since May 2026. By impersonating IT help desk personnel, attackers are exploiting the psychological trust employees place in security-related administrative requests, using the pretext of "passkey setup" to bypass traditional security barriers and gain deep, persistent access to sensitive cloud infrastructure.

The Anatomy of the Social Engineering Campaign

The attack sequence typically begins with direct communication, bypassing corporate email filters by reaching victims on their personal mobile devices. Attackers initiate contact via voice calls or SMS, occasionally utilizing Microsoft Teams messages originating from previously compromised accounts within the same organization. This adds a layer of perceived legitimacy, as the victim believes they are communicating with a trusted colleague or a legitimate IT support representative.

During these interactions, the threat actor creates a sense of urgency, informing the employee that their account requires an immediate update to their passkey, multifactor authentication (MFA), or single sign-on (SSO) configuration. The stated goal is to prevent service disruption, a tactic designed to discourage the victim from pausing to verify the request through official channels.

Researchers Warn: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers -- Campus Technology

Once the victim is hooked, they are directed to a malicious website designed to mimic a legitimate Microsoft login portal. While the campaign is themed around "passkeys," the technology itself is not being hacked. Instead, the attackers use the request as a diversion to facilitate two primary exploitation techniques: Adversary-in-the-Middle (AiTM) phishing and device-code authentication abuse.

In an AiTM scenario, the attacker intercepts the communication between the user and the legitimate service, capturing credentials and active session tokens in real time. Conversely, in device-code phishing, the victim is tricked into entering a code provided by the attacker into their own device, effectively authorizing a client application controlled by the threat actor to access their enterprise resources.

Chronology of the 2026 Campaign

Since May 2026, Microsoft has documented a steady escalation in this activity across multiple sectors. The timeline of a typical incident follows a structured pattern of reconnaissance and escalation:

  1. Initial Contact (T-minus 0): The attacker initiates contact via phone or messaging, establishing rapport and setting the premise of an IT security update.
  2. Credential Harvesting (T+10 minutes): The user is directed to a spoofed portal where they unknowingly provide their credentials or authorize an attacker-controlled device.
  3. Primary Compromise (T+20 minutes): The attacker gains access to the user’s account. Anomalous logins from unmanaged devices are recorded by security logs.
  4. Reconnaissance (T+30 to T+60 minutes): Using Microsoft Graph, the attacker enumerates the user’s environment, mapping out groups, permissions, and available applications.
  5. Persistence Establishment: The attacker registers new, malicious authentication methods—such as external phone numbers or rogue authenticator apps—ensuring they can maintain access even if the victim changes their password.
  6. Exfiltration: The attacker pivots to SharePoint Online, OneDrive, and REST-based email APIs to harvest sensitive documents, proprietary data, and internal communications.

Threat Actor Attribution and Strategic Intent

Microsoft has attributed these campaigns to several high-profile threat actor groups, most notably Storm-3121 and Storm-3032. These groups have historically demonstrated expertise in identity-centric attacks. Storm-3121 is frequently associated with initial access brokerage, often acting as a precursor to large-scale data extortion operations carried out by groups such as ShinyHunters or Falcon. Storm-3032, a splinter group of the defunct BlackFile syndicate, now operates under the Helix banner, focusing on high-value data theft and long-term espionage within corporate tenants.

Researchers Warn: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers -- Campus Technology

The strategic intent behind these campaigns is not merely short-term data theft. By registering their own MFA devices, these actors ensure that they can bypass standard password resets. This transformation from a temporary session hijack to a persistent, legitimate-looking "employee" presence allows for long-term intelligence gathering, which is increasingly being sold on the dark web to larger ransomware syndicates or state-sponsored actors.

Data-Driven Implications for Enterprise Security

The success of these attacks highlights a critical gap in organizational security: the reliance on human vigilance in the face of increasingly realistic social engineering. According to recent industry cybersecurity metrics, identity-based attacks now account for over 80% of successful enterprise breaches. The move toward passkeys and FIDO2-compliant hardware is intended to mitigate this, yet as this campaign demonstrates, the transition phase—where employees are learning to use new tools—is a prime window of vulnerability.

The high-volume activity observed through Microsoft Graph, where attackers can search through thousands of documents in under an hour, underscores the danger of lateral movement. Once an attacker gains a foothold in an identity provider, the "blast radius" is limited only by the permissions assigned to that specific user. If that user has broad access to corporate SharePoint or OneDrive repositories, the entire organization’s intellectual property is at risk.

Mitigating the Threat: A Proactive Stance

Microsoft’s security researchers have issued a set of rigorous recommendations for IT administrators looking to fortify their environments against these tactics:

Researchers Warn: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers -- Campus Technology
  • Enforce Phishing-Resistant MFA: While attackers are using the "passkey" narrative to trick users, the solution remains moving to true phishing-resistant methods. Enforcing FIDO2 security keys or Windows Hello for Business via Conditional Access policies makes it nearly impossible for an AiTM attack to succeed, as the authentication is bound to the physical device and the specific domain.
  • Restrict Authentication Flows: Organizations should proactively block device-code and authentication-transfer flows if they are not explicitly required by business workflows. These are high-risk vectors that serve little purpose for the average end-user.
  • Continuous Monitoring: Administrators should configure alerts for "impossible travel" scenarios, logins from unmanaged or unusual devices, and, crucially, the addition of new authentication methods. A sudden registration of an authenticator app by a user who has not been prompted by the internal IT team should trigger an immediate account lockout and investigation.
  • Behavioral Analytics: Utilize advanced identity protection tools to detect abnormal Microsoft Graph queries. Attackers enumerating files or attempting to scrape mass amounts of email data through REST APIs often exhibit behavioral patterns that differ significantly from a standard user’s workflow.

The Broader Impact on Identity Management

The emergence of "passkey-themed" social engineering serves as a sobering reminder that there is no "silver bullet" for cybersecurity. As technology evolves, so too do the tactics of threat actors who exploit the weakest link in the security chain: human behavior.

The distinction here is subtle but vital. The attackers are not defeating the cryptography behind passkeys. Instead, they are manipulating the culture of the modern workplace, where IT help desks are expected to be available, helpful, and technologically advanced. By mimicking the helpfulness of IT staff, they weaponize the very processes meant to protect the enterprise.

For organizations currently rolling out passwordless initiatives, the primary takeaway is that the technical deployment is only half the battle. Employee awareness training must now specifically address the "passkey setup" narrative, ensuring that users understand that legitimate IT departments will never ask them to enter codes or passwords on an external or unverified portal. Furthermore, the reliance on identity as the primary perimeter means that organizations must adopt a "zero trust" posture, where every authentication request, even those seemingly originating from within the organization, is treated with suspicion until verified by automated, hardware-backed identity controls.

As the industry moves toward a future where passwords become a relic of the past, the "identity war" will continue to escalate. The events of 2026 provide a clear roadmap for how threat actors are adapting to these changes, and for defenders, the mandate is clear: tighten the controls around how authentication methods are registered, monitored, and used, or risk losing the very identity services that serve as the backbone of the modern digital enterprise.

Leave a Reply

Your email address will not be published. Required fields are marked *