Researchers at Microsoft are tracking a social engineering campaign that uses passkey-themed lures to trick users into granting persistent access to their accounts and online work environments.
“The attack often begins with a seemingly routine call or message on a user’s personal phone number from someone claiming to be from the organization’s IT helpdesk,” the researchers write. “The caller creates a sense of urgency, explaining that a passkey, multifactor authentication (MFA), or single sign-on (SSO) configuration must be updated immediately to avoid disruption. Employees are directed to a website that closely resembles a legitimate Microsoft sign-in experience and may receive the link through SMS messages sent directly to their personal mobile phones.”
The attacker’s goal is to trick the victim into performing actions that will allow the attacker to intercept device codes and session tokens, rather than stealing the victim’s password.
“Despite the frequent use of passkey-themed lures, passkey enrollment is often not the actor’s true objective,” Microsoft explains. “Instead, the passkey narrative serves as a convincing pretext to guide victims through adversary-in-the-middle (AiTM) phishing or device-code authentication flows. In AiTM scenarios, the actor captures credentials and session tokens; in device code attacks, the victim unknowingly authorizes access on the actor’s behalf. This initial interaction may leave very little forensic evidence. If the victim opens the phishing link on a personal mobile device that is not onboarded to Microsoft Defender for Endpoint, the related activity may be absent from endpoint telemetry.”
The threat actors behind this activity perform extensive reconnaissance on the targeted organizations to craft highly personalized social engineering attacks. Microsoft attributes the attacks to various threat actors associated with extortion groups.
“Together, the phone-based social engineering, personalized targeting, trusted internal messaging, and rapidly changing phishing infrastructure form the opening chapter of a highly coordinated intrusion designed to blend technical deception with human trust,” Microsoft concludes.
Microsoft has the story: https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/
