Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Attackers Phish Microsoft Passkey and MFA Updates to Hijack 365 Accounts

Microsoft researchers report a phishing campaign that tricks users into approving bogus passkey, MFA, or SSO updates, allowing attackers to capture valid authentication tokens and access Microsoft 365 data. The tactic highlights the need for strong authentication governance and security‑awareness controls for audit readiness.

LiveThreat™ Intelligence · 📅 September 20, 2026· 📰 techrepublic.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
techrepublic.com

Attackers Phish Microsoft Passkey and MFA Updates to Hijack 365 Accounts

What Happened — Microsoft security researchers observed a new phishing campaign that began in May 2026. Attackers impersonate IT staff and ask employees to “update” a passkey, MFA, or SSO setting, using either an attacker‑in‑the‑middle site or a device‑code flow to capture a valid authentication token. Compromised accounts are then used to enumerate SharePoint, OneDrive and Exchange Online data.

Why It Matters for Trust & Control Assurance

  • The scenario tests the control objective of managing authentication methods and verifying user‑initiated changes – a core element of any continuous control‑assurance program.
  • Successful abuse shows gaps in security awareness training and real‑time monitoring of credential‑change requests, which must be documented as evidence for audit readiness.

Who Is Affected – Enterprises using Microsoft 365 (cloud productivity suites) across all verticals; particularly organizations with large remote workforces.

Recommended Actions –

  • Enforce a policy that any passkey, MFA, or SSO change must be approved through a verified, out‑of‑band channel (e.g., signed email from a known admin address).
  • Deploy continuous monitoring of authentication events and generate alerts for anomalous device‑code flows or MFA updates.
  • Refresh security‑awareness training to include the “passkey update” phishing vector and simulate it in phishing‑test campaigns.

Source: TechRepublic – Microsoft Passkey Phishing Hook

Technical Notes – The attack leverages legitimate Microsoft sign‑in flows (device‑code grant) and an attacker‑in‑the‑middle proxy to harvest session tokens. No new CVE is involved; the weakness is procedural – users are tricked into authorizing a device they do not control.

Source: same as above

📰 Original Source
https://www.techrepublic.com/article/news-microsoft-passkey-phishing-mfa-device-code/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →