Attackers Phish Microsoft Passkey and MFA Updates to Hijack 365 Accounts
What Happened — Microsoft security researchers observed a new phishing campaign that began in May 2026. Attackers impersonate IT staff and ask employees to “update” a passkey, MFA, or SSO setting, using either an attacker‑in‑the‑middle site or a device‑code flow to capture a valid authentication token. Compromised accounts are then used to enumerate SharePoint, OneDrive and Exchange Online data.
Why It Matters for Trust & Control Assurance
- The scenario tests the control objective of managing authentication methods and verifying user‑initiated changes – a core element of any continuous control‑assurance program.
- Successful abuse shows gaps in security awareness training and real‑time monitoring of credential‑change requests, which must be documented as evidence for audit readiness.
Who Is Affected – Enterprises using Microsoft 365 (cloud productivity suites) across all verticals; particularly organizations with large remote workforces.
Recommended Actions –
- Enforce a policy that any passkey, MFA, or SSO change must be approved through a verified, out‑of‑band channel (e.g., signed email from a known admin address).
- Deploy continuous monitoring of authentication events and generate alerts for anomalous device‑code flows or MFA updates.
- Refresh security‑awareness training to include the “passkey update” phishing vector and simulate it in phishing‑test campaigns.
Source: TechRepublic – Microsoft Passkey Phishing Hook
Technical Notes – The attack leverages legitimate Microsoft sign‑in flows (device‑code grant) and an attacker‑in‑the‑middle proxy to harvest session tokens. No new CVE is involved; the weakness is procedural – users are tricked into authorizing a device they do not control.
Source: same as above