Skip to content
Tech News
← Back to articles

Passkey-themed phishing attacks lead to Microsoft 365 data theft

read original get YubiKey 5C NFC Security Key → more articles
Why This Matters

Microsoft reports that extortion crews tied to ShinyHunters and Helix are exploiting the security industry's own passkey/MFA messaging as phishing bait, calling and texting employees while posing as IT help desks. Rather than enrolling passkeys, they funnel victims into adversary-in-the-middle sites and device-code flows to steal session tokens and raid Microsoft 365 data. It's a reminder that phishing-resistant technology doesn't help if attackers can talk users around it.

Key Takeaways
Worth a Look

YubiKey 5C NFC Security Key — Phishing pages that harvest codes and session tokens fall flat against a hardware security key, since FIDO2 authentication is bound to the real site's domain. The YubiKey 5C NFC works over USB-C and NFC with Microsoft accounts, Google, and password managers, making it a practical upgrade for anyone tired of MFA prompts they can't trust.

See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.

The activity has been observed since May 2026 and begins with the attackers researching targeted organizations and employees before calling or messaging victims while impersonating corporate IT help desks.

The attackers tell employees that they must urgently update a passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to avoid losing access to corporate systems.

Victims are then directed to phishing sites designed to resemble legitimate Microsoft login pages, with links sometimes sent through SMS messages to employees' personal phones.

Microsoft says that while the lures frequently revolve around passkeys, the attackers are not attempting to enroll a passkey.

Instead, the passkey lures are used to trick targeted employees into signing in to adversary-in-the-middle (AiTM) phishing sites or using device-code authentication flows.

AiTM attacks allow the threat actors to capture credentials and session tokens. Device code phishing tricks victims into authorizing access to their account via an attacker-controlled client using Microsoft's legitimate authentication pages.

Microsoft says the attackers conduct extensive research before targeting employees.

"The actor appears to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms," explains Microsoft.

The threat actors also register phishing domains that combine company names with words related to passkeys, SSO, key synchronization, account setup, and identity verification.

... continue reading