Passkey Phishing Attacks Compromise Microsoft Identity Cloud
Passkeys were originally conceived as the ultimate cure for phishing, yet threat actors have ingeniously discovered a darker role for this technology. Currently, an attacker merely needs to telephone an employee while masquerading as IT support. By fabricating an urgent requirement to configure a passkey or Multi-Factor Authentication (MFA), the fraudster expertly guides the victim through a convoluted procedure. Consequently, the attackers successfully seize complete control over the corporate Microsoft account.
The Deceptive Social Engineering Playbook
This nefarious scenario typically commences with a phone call or text message directed to the personal device of the employee. A counterfeit technical support specialist ominously warns of impending access restrictions and insists upon an immediate update to their passkey, MFA, or Single Sign-On configurations. Subsequently, the victim receives a malicious link leading to a fraudulent page that is virtually indistinguishable from the legitimate Microsoft login portal. The criminals meticulously research the organizational structure beforehand, crafting URLs that seamlessly incorporate the company name to create an illusion of familiarity.
Exploiting AiTM and Device Code Authorization
The purported passkey configuration frequently serves merely as a highly persuasive cover story. The victim is subtly maneuvered through Adversary-in-the-Middle (AiTM) phishing or manipulative device code authorization protocols. In the former scenario, the criminals illicitly intercept the credentials and session tokens. In the latter, the employee unwittingly enters a provided code onto the authentic Microsoft portal, thereby granting explicit access to the attacker’s client. Following this fatal confirmation, standard MFA protocols can no longer impede the exploitation of the captured session.
Establishing Persistence and Automated Reconnaissance
Having entrenched themselves within the compromised account, the attackers ruthlessly strive to transform their ephemeral access into enduring persistence. They swiftly append their own telephone number, authenticator application, or software OTP token directly to the victim’s profile. This newly established factor permits the criminals to bypass all subsequent security checks without requiring the account owner. They maintain this unrestricted access until diligent administrators forcibly revoke active sessions and purge the unauthorized authentication methods.
The ensuing phase involves aggressive, automated reconnaissance orchestrated via the Microsoft Graph API. The intruders systematically enumerate users, groups, roles, permissions, and accessible enterprise applications while scrutinizing existing authentication methodologies. Ultimately, they pivot toward lucrative targets like SharePoint, OneDrive, and Exchange. Microsoft has documented massive, programmatic extraction of files, mailboxes, and sensitive attachments. Furthermore, disparate stages of the assault frequently utilize distinct IP addresses and proxies, severely complicating efforts to reconstruct the complete attack chain.
Analyzing the Microsoft Threat Landscape
In numerous instances, the initial minutes following the compromise unlocked immediate access to the application directory, the user profile, and critical account management interfaces. Subsequent actions rapidly targeted corporate documents and vital correspondence. If the employee unfortunately opened the phishing link on a personal smartphone lacking Microsoft Defender for Endpoint, security teams might possess almost zero telemetry regarding the initial breach vector. Occasionally, the sole evidence consists solely of the employee recounting a peculiar phone call or SMS message.
Microsoft has continuously monitored this orchestrated campaign since at least May 2026. The corporation unequivocally links these sophisticated operations to several distinct threat actor groups, including Storm-3121 and Storm-3032. The former specializes in securing initial access to facilitate the ShinyHunters and Falcon ransomware operations. Meanwhile, Storm-3032 comprises former BlackFile affiliates currently operating under the Helix moniker.
Crucial Defense Strategies and Mitigation
To establish robust defenses, Microsoft advises organizations to monitor behavioral sequences rather than merely tracking isolated, suspicious IP addresses. Security teams should actively search for anomalous logins followed closely by the registration of novel MFA methods, aggressive Graph API reconnaissance, and erratic file or email interactions. The company further recommends strictly limiting the registration of new authentication tools via Conditional Access policies. Organizations should mandate the use of managed devices, disable device code authorization where entirely unnecessary, and universally enforce phishing-resistant methodologies such as FIDO2, passkeys, or Windows Hello for Business.
The BlackFile syndicate previously employed highly similar mechanics: operators systematically telephoned employees under the guise of IT support, demanding a transition to passkeys or an MFA update. Following the account hijacking, they registered their own devices and ruthlessly pillaged data from Microsoft 365, Salesforce, and Zendesk. Another terrifying attack variation emerged via the EvilTokens service, constructed around the OAuth 2.0 Device Code flow. The user inputs a code on the legitimate Microsoft page but actually validates a hostile session. The criminals subsequently acquire a powerful access token, allowing them to manipulate the corporate account without ever re-entering the password.
Even the passkeys themselves cannot entirely eradicate this problem. In August, security experts demonstrated the “Pass-ta-key” technique, which maliciously exploits the synchronization idiosyncrasies of passkeys within the Windows ecosystem. The overarching conclusion regarding these assaults is singular and stark: a cryptographically robust login mechanism ultimately fails to protect an account if an attacker can successfully persuade an employee to legitimize a hostile session or register a fraudulent access factor.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.