Microsoft alerts to complex impersonation scheme that hijacks passkey logins
Microsoft has issued a warning about a newly uncovered campaign that combines sophisticated impersonation tactics with passkey phishing to hijack corporate cloud accounts. The operation targets users of Microsoft 365 services, tricking them into updating their authentication credentials through a counterfeit IT support call. By exploiting the growing adoption of passkeys, which are marketed as resistant to traditional phishing, the attackers create a pathway to access sensitive data stored in the Microsoft cloud.
The attackers initiate contact by posing as internal help‑desk personnel, often referencing recent security updates or device upgrades. Victims are instructed to follow a link that appears to lead to a Microsoft sign‑in page, but in reality routes them through an adversary‑in‑the‑middle server that mimics the genuine login interface. When users enter their new passkey information, the counterfeit site captures the data and forwards it to the threat actors, effectively granting them the same privileges as the legitimate user.
Once the credentials are in hand, the criminals move laterally across the compromised tenant, harvesting files from SharePoint libraries, OneDrive accounts, and Exchange mailboxes. Security analysts have observed bulk exfiltration of documents, spreadsheets, and email archives, suggesting that the campaign is aimed at data theft rather than immediate ransomware deployment. The stolen material can be sold on underground markets or used for further spear‑phishing attacks against business partners.
The episode underscores a paradox in modern authentication: while passkeys eliminate the need for passwords and reduce exposure to classic phishing emails, they do not protect against social engineering that convinces users to willingly surrender the credential. Experts note that the technique is a reminder that any authentication factor is vulnerable if the user is deceived into providing it to a malicious endpoint. Organizations are therefore urged to reinforce verification procedures beyond the technical safeguards.
Microsoft recommends that enterprises train staff to treat unsolicited IT calls with suspicion, verify caller identity through established channels, and avoid clicking links sent during such conversations. Enabling additional layers such as conditional access policies, device compliance checks, and real‑time monitoring for anomalous sign‑in activity can help detect and block unauthorized access. The company says it is working with law‑enforcement partners to trace the infrastructure behind the operation and will release further guidance as the investigation proceeds.
Comments (0)
Be the first to comment.
Join the discussion