Insights

Passkey-Themed Phishing Still Compromising Identities

A secure laptop sits on a clean desk with passkey-style authentication interface visible on screen showing verified sign-in status
Security research has documented this persistent pattern since spring 2026: attackers calling or messaging you about passkeys, MFA refresh, or SSO configuration updates direct you to a fake authentication portal that steals your session token. Do not click links from unexpected callers. Verify through another channel first.

TL;DR

Attackers use passkey and MFA enrollment as social engineering lures for Microsoft 365 identity theft. The telltale sign is urgency tied to authentication methods.

How the attack works

A caller claims to be IT support or says they work for your organization, then creates urgency about updating passkeys or MFA settings. You are directed to a website resembling the real sign-in experience, either via phone link or SMS sent directly to your personal mobile device.

The passkey enrollment is not the true objective. You may think you are enrolling in a new authentication method, but instead you approve an authentication request that attacker infrastructure controls. The stolen session cookie gives the attacker persistent access to your cloud identity.

Once inside, attackers download files from SharePoint and OneDrive, collect emails through REST APIs, and move laterally across accounts. Security researchers observe this sequence consistently since early 2026.

If you see suspicious activity

If you notice unusual sign-ins, unknown devices, or unexpected passkey enrollments:

  1. Revoke all active sessions immediately from the Microsoft account portal.
  2. Remove unauthorized authentication methods. Check for unknown registered devices or passkeys and revoke them.
  3. Check file history on SharePoint and OneDrive for documents accessed without your knowledge.
  4. Reset passwords for any accounts where you shared the Microsoft password with vendors or partners.

Your IT provider should check these items

If you use managed services, ask about reviews of:

  • Sign-in logs for unusual patterns, especially locations you have never visited.
  • Authentication method changes — alerts when unknown devices enroll passkeys or new MFA methods register.
  • Microsoft Graph activity reports. These show bulk actions from compromised accounts — high-volume downloads, email forwarding rules, SharePoint document moves.

This attack remains common in 2026

Even with advanced security controls, voice and messaging phishing remain highly effective. The caller creates urgency and directs you to authenticate through their infrastructure. These callers can be automated or manual — the distinction matters less than whether you recognize them as unexpected contacts.

The practical path forward

Treat MFA-related outreach with skepticism. Urgent requests to enroll in passkeys or update authentication methods via unsolicited call, SMS, or email warrant independent verification first.

Enable alerts on sign-in and authentication method changes so your admin sees notifications when unknown devices register.

Get a free security review

If you would like help ensuring updates are flowing to every machine you rely on, we look at that for you. Our free 30-minute IT review will check whether your current authentication controls and incident response plan can withstand social engineering attempts.

We work with small businesses, schools, churches, and nonprofits around Washington County. If you need help reviewing your Microsoft 365 security posture or want a second opinion on how to respond to suspicious MFA activity, we are available for that conversation today. Book your free review.