Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. It can defeat MFA protections.
The campaign starts with calls and texts to employees. Attackers pose as IT support, claim a passkey, MFA, or single sign-on setting needs attention, and direct targets to lookalike sign-in pages.
Compromised accounts can also send lures through Microsoft Teams. Microsoft researchers identified the activity across cloud intrusions observed since May 2026.
They found unusual sign-ins followed by new authentication methods, Microsoft Graph queries, and downloads from SharePoint, OneDrive, and email services. The pattern indicates deliberate collection from compromised cloud identities.
Microsoft said in a report shared with Cyber Security News (CSN) that the attackers rotate infrastructure and may use separate connections for sign-in, discovery, and collection. This can resemble normal use while attackers map organizations and take files or messages.
Hackers Use Passkey-Themed Phishing
The passkey story is a pretext, not an effort to enroll a passkey. Victims can be put into an adversary-in-the-middle phishing flow, where a fake site relays their sign-in to the real service and captures credentials and session tokens.
They may instead complete a device-code sign-in that grants access to an attacker-controlled client. A user can complete MFA and still surrender a usable cloud session.
A BigBear session theft campaign showed phishing pages can steal proof that MFA was completed. Authentication prompts deserve the same scrutiny as password requests, after an unexpected call or text.
In one sequence, an attacker signed in from an unmanaged device, then opened account portals with the same session.
In another, device-code approval produced a token replayed to bypass MFA. Researchers also saw attackers return using compromised credentials paired with an authenticator method registered earlier.
After entry, operators seek lasting access by adding a phone number, authenticator application, or software one-time-password token under their control. A password reset may not evict them if active sessions, refresh tokens, or rogue authentication methods remain. Teams should investigate risky sign-ins alongside every newly registered factor.
Organizations have faced Entra passkey enrollment attacks using phone impersonation. Employees should confirm unexpected helpdesk requests through a known internal channel, never a number or link given by the caller. A verified reporting route for authentication requests can stop the attack before access is granted.
From Account Access to Cloud Collection
Once persistence is established, the attackers use Microsoft Graph to learn what the user can reach. They enumerate users, groups, roles, applications, permissions, sites, drives, folders, files, mailboxes, and attachments. One request may be normal, but broad discovery followed by content retrieval reveals a coordinated intrusion.
The operators then target SharePoint Online and OneDrive for Business with high-volume file access and downloads. Some cases extended to Exchange Online REST API access to email content. Microsoft observed collection often below 1,000 files or emails per hour, a pace that can avoid attention while continuing for hours or days.
This resembles device code phishing abuse, in which a legitimate approval page is abused to gain access without taking a browser cookie. The damage follows when criminals search repositories and collect accessible data.
Defenders should correlate identity, Graph, SharePoint, OneDrive, and Exchange records, rather than treating an IP address or domain as conclusive. Important signals include an unusual sign-in followed by MFA enrollment, intensive Graph discovery, anonymous-proxy access, automated downloading, and concentrated mailbox or attachment searches.
For a confirmed compromise, teams should revoke active sessions and refresh tokens, reset credentials, remove unauthorized authentication methods and mailbox rules, then require secure MFA registration. They should require phishing-resistant MFA, limit cloud access from unmanaged devices, restrict device-code flows unless needed, and review application consent plus privileged Graph permissions.
The actions reflect lessons from M365 session hijacking cases, where stolen sessions may survive a password reset. Training should cover voice, text, and Teams scams, while cloud and mailbox auditing can prevent a routine-looking passkey update from becoming a data breach.
| Type | Indicator | Description |
|---|---|---|
| Domain | passkeyhelpdesk[.]com |
Passkey support lure |
| Domain | secure-passkey[.]com |
Passkey security |
| Domain | setupmypasskey[.]com |
Passkey setup |
| Domain | add-passkey[.]com |
Passkey enrollment |
| Domain | integratedsso[.]com |
SSO |
| Domain | oktasession[.]com |
Identity-provider session |
| Domain | keysyncos[.]com |
Key synchronization |
| Domain | oskeysync[.]com |
Key synchronization |
| Domain | oskeysetup[.]com |
Key setup |
| Domain | oskeyregister[.]com |
Key registration |
| Domain | syncmykey[.]com |
Key synchronization |
| Domain | myconnectkey[.]com |
Key connection |
| Domain | oskeyconnect[.]com |
Key connection |
| Domain | validationsetupac[.]com |
Account validation and setup |
| Domain | portalsetuphub[.]com |
Portal setup |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
The post Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data appeared first on Cyber Security News.
