Microsoft Warns of Passkey-Themed Phishing and Cloud Identity Compromise

Microsoft has recorded active intrusions into cloud accounts in which attackers exploit phone calls and text messages with urgent requests to change a passkey or MFA.

On September 9, 2026, Microsoft Security Research warned of active intrusions into cloud accounts observed since May 2026. The attacks involve passkey-themed phishing: attackers impersonate IT support and convince users that they urgently need to update their passkey, multifactor authentication (MFA), or single sign-on (SSO) settings.

Importantly, the published scenario does not describe a cryptographic break of passkeys. The passkey lure serves as a credible-sounding pretext for gaining account access by other means: adversary-in-the-middle (AiTM) phishing or device-code phishing abuse. In both cases, social engineering plays the decisive role.

Passkey-themed phishing is not a passkey compromise

In AiTM phishing, the attacker obtains credentials and session tokens, or intercepts them during sign-in. In device-code phishing, the victim may authorize access for a client controlled by the attacker. The attack therefore does not depend on bypassing passkey security properties, but on persuading the user to take an action that benefits the attacker.

A phone call or text message can create the impression that it is a routine IT service intervention. The user is presented with an urgent request to register a new method, change MFA, or modify SSO. Microsoft warns that this urgency and apparent technical legitimacy are intended to lead the victim into a phishing flow or authorization of a malicious client.

Deploying phishing-resistant sign-in therefore does not cover every path to identity compromise. Authentication method registration, account recovery, device-code flow, and protection of post-sign-in sessions also remain relevant.

What Microsoft observed after access was obtained

In confirmed compromises, Microsoft recorded attackers adding their own authentication methods. This was followed by environment reconnaissance through Microsoft Graph, downloading content from SharePoint and OneDrive, and collecting emails through REST API.

The scope of access depends on the permissions of the compromised account. A successful attacker may therefore work with corporate email, files in SharePoint or OneDrive, and other cloud applications to which the victim has authorized access.

Microsoft assesses the activity as consistent with automated data collection and possible exfiltration. However, the public analysis does not state the number of affected organizations, the volume of potentially stolen data, or independently verified damage. Microsoft also did not confirm attribution of the campaign to a specific threat group.

Account checks and response to compromise

For confirmed compromises, Microsoft recommends reviewing unusual sign-ins and changes to authentication methods. Active sessions should then be revoked, and unauthorized authentication methods should be removed.

Security teams can focus especially on an event chain in which an unusual sign-in is followed by registration of a new authentication method or issuance of a token. Other signals include activity in Microsoft Graph and bulk data downloads from SaaS services. For users, it is important to have a clearly defined, verified process for changing passkeys, MFA, and SSO, rather than following instructions from an unexpected call or text message.

Further developments will show whether Microsoft or other security teams publish actor attribution, a larger campaign scope, or confirmed cases of exfiltration. The currently available findings already document a specific attack model targeting cloud identities in which passkeys are used as a lure, not as a protection that has been directly defeated.

Sources

  • Microsoft Security Blog – Microsoft’s primary analysis confirms the observed intrusions, the passkey-themed lure, AiTM and device-code phishing, activity in Microsoft Graph, and recommended remediation steps.
  • Microsoft Security Blog – Confirms a separate, unrelated financially motivated phishing campaign abusing ActiveCampaign infrastructure; it is not evidence that this infrastructure is connected to the passkey campaign.
  • TechRadar – Independently summarizes that Microsoft warned about campaigns targeting cloud account compromise and data collection.

Verified and updated: 09/13/2026 15:20

Sharing