Tech News
← Home  ·  All topics

Passkey Phishing

1 GoKawiil brief on this topic

ShinyHunters-linked hackers use fake passkey alerts to breach Microsoft 365 accounts

Microsoft has detailed a social engineering campaign, active since May 2026, in which attackers tied to groups like ShinyHunters and Helix pose as corporate IT help desks and warn employees their passkey, MFA, or SSO settings need urgent updating. Victims are steered to convincing fake Microsoft login pages—often via SMS to personal phones—where attackers harvest credentials and session tokens using adversary-in-the-middle and device-code phishing techniques, rather than actually registering new passkeys.