Passkey phishing is being used to hijack Microsoft 365 accounts and steal cloud data. Microsoft says the social engineering campaign combines phone calls, text messages and convincing sign-in pages to overcome multifactor authentication.
The activity has appeared across cloud intrusions observed since May 2026. After gaining access, attackers add authentication methods, query Microsoft Graph and collect information from SharePoint, OneDrive and email.
How the passkey phishing campaign begins
The campaign starts with direct contact rather than an unsolicited email alone. Attackers call or text employees while impersonating IT support, giving the interaction a sense of immediacy and authority.
The employee is told that a passkey, MFA or single sign-on setting requires attention. The attacker then directs the target to a lookalike Microsoft sign-in page designed to capture or relay the authentication process.
This combination is important. The phone conversation provides a persuasive pretext, while the imitation sign-in page gives the victim an apparently familiar place to complete the requested action. References to passkeys and security configuration can also make the request sound like a legitimate account upgrade.
Compromised accounts may then be used to send further lures through Microsoft Teams. Messages originating from a genuine organisational identity are more likely to appear credible, allowing the campaign to move beyond the initially targeted employee.
Why MFA does not necessarily stop the attack
Microsoft reports that the operation can defeat MFA protections. Rather than simply testing a stolen password against a conventional login page, the attackers manipulate the user into participating in an authentication flow under a false pretext.
Once the intruder has established access, the addition of a new authentication method can help maintain control of the identity. This is a significant stage because it may give the attacker another way to authenticate, even after the original social engineering interaction has ended.
Passkey phishing leads to cloud identity compromise
Microsoft researchers linked the passkey phishing activity to a recognisable sequence of cloud events. They identified unusual sign-ins followed by newly registered authentication methods, Microsoft Graph queries and downloads from Microsoft 365 services.
The observed progression indicates that the attackers are not stopping at account takeover. They are using the compromised identity to understand the environment, locate useful information and deliberately collect data held in the cloud.
The main actions reported in the campaign include:
- Contacting employees by phone call or text message while posing as IT support.
- Claiming that a passkey, MFA or single sign-on configuration needs attention.
- Sending the target to a lookalike sign-in page.
- Using compromised Microsoft 365 accounts to distribute additional lures through Teams.
- Signing in unusually and registering new authentication methods.
- Querying Microsoft Graph to discover information available to the compromised identity.
- Downloading files or messages from SharePoint, OneDrive and email services.
Microsoft Graph is particularly relevant because it provides a unified way to interact with data and services across Microsoft 365. Queries made after compromise can help attackers map what an account can access before they begin extracting content.
SharePoint, OneDrive and email data targeted
The collection activity affects information already available to the compromised user. Depending on the person’s role and permissions, this may include shared documents in SharePoint, individual or synchronised files in OneDrive, and business communications held in email.
This means the practical impact can vary between accounts. A user with broad access to shared sites, sensitive correspondence or important project material may expose substantially more data than an account with tightly limited permissions.
The cloud-focused pattern also changes what defenders need to review. An incident may not involve malware on a laptop or a large transfer from a corporate file server. Instead, the evidence can sit in identity, authentication, Graph and Microsoft 365 audit records.
Timeline and current exploitation status
Microsoft identified the activity across cloud intrusions observed since May 2026. On 9 September 2026, the company published its report describing passkey-themed social engineering that leads to identity and cloud compromise.
The report shows that this is observed exploitation, not a theoretical technique or an unexploited software flaw. Attackers have used the approach against employees and followed successful account access with discovery and data collection.
Microsoft also found that the operators rotate their infrastructure. Separate connections may be used for sign-in, discovery and collection, making the sequence less obvious than an intrusion conducted from one consistent source.
This separation can help malicious activity resemble ordinary cloud use. An attacker may authenticate through one connection, use another to map accessible resources, and collect files or messages through further infrastructure. Looking at any single action in isolation may therefore provide an incomplete picture.
No specific vulnerable Microsoft 365 software version is identified in the reported material. The campaign abuses users, authentication workflows and legitimate cloud capabilities rather than relying on a disclosed product vulnerability with a patchable version range.
Why this Microsoft 365 campaign matters
The incident demonstrates that stronger authentication is not automatically phishing-proof. A passkey-themed story can be used as the lure itself, especially when a caller impersonating IT guides an employee through the steps.
It also highlights the value of a cloud identity after compromise. One successful login can provide access to messages, documents and application interfaces, while a newly added authentication method may extend the attacker’s control.
What organisations should do now
Defenders should hunt for the specific sequence Microsoft observed, rather than relying only on isolated sign-in alerts. Priority should be given to accounts showing unusual access followed by authentication changes, Graph activity or substantial cloud downloads.
- Review newly added authentication methods and confirm them with the affected user through a trusted channel.
- Correlate unusual sign-ins with Microsoft Graph queries and subsequent SharePoint, OneDrive or email access.
- Investigate Teams messages that direct colleagues to passkey, MFA or single sign-on pages.
- Tell staff that genuine IT teams should not pressure them by phone or text to use an unfamiliar sign-in link.
- Revoke active sessions and unauthorised authentication methods when compromise is suspected, then assess what cloud data was accessed.
Because the operators rotate connections, investigations should focus on behaviour across the account rather than one IP address. The strongest signal is the combined chain from social engineering and unusual authentication to persistence, discovery and collection.
Originally reported by cybersecuritynews.com.






