Passkey Phishing Is Here — and It’s Hitting Microsoft 365 Hard

Passkeys were supposed to kill phishing. Instead, attackers are now weaponizing the hype around passkeys to hijack Microsoft 365 accounts across U.S. enterprises, exfiltrating terabytes of email, SharePoint, and OneDrive data in campaigns that have been running since at least May 2026.

Microsoft disclosed this week that multiple cybercrime groups — tracked as Storm-3121 and Storm-3032 (also known as UNC6671 or Cordial Spider) — are impersonating IT help desks and using passkey-themed lures to steal credentials and session tokens from corporate users. It is a stark reminder that even the best authentication technology is only as strong as the humans who adopt it.

How the Attack Works

The campaign begins with a phone call or text message. The attacker, posing as internal IT support, tells the target there is an urgent problem with their passkey, MFA, or SSO configuration. The victim is then directed to a convincing lookalike Microsoft sign-in page hosted on one of dozens of malicious domains — names like passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, and integratedsso[.]com.

What makes this more dangerous than a conventional phishing page is the technical sophistication behind it. The attackers deploy adversary-in-the-middle (AitM) proxy infrastructure that relays the victim’s credentials to the real Microsoft login service in real time. This means the phishing page can capture not just passwords, but the session tokens generated after legitimate MFA completion. In effect, the attacker walks through the front door using the victim’s authenticated session.

In some variants, the attackers abuse Microsoft’s device-code authentication flow — a legitimate feature designed for devices without browsers — to grant their own client full access to the victim’s account without ever needing to intercept a password directly.

Once inside, the attackers move fast to cement their access. They register new MFA methods under their control: new phone numbers, authenticator apps, and software OTP tokens. This gives them persistent access even if the victim later changes their password.

What Happens After the Breach

Post-compromise activity follows a methodical playbook. Attackers use the Microsoft Graph API to conduct deep reconnaissance — enumerating users, groups, roles, applications, permissions, sites, drives, folders, files, mailboxes, and attachments across the entire tenant.

Then the exfiltration begins. Data is pulled from SharePoint Online, OneDrive for Business, and Exchange Online inboxes. According to Microsoft, the attackers pace their downloads deliberately — typically below 1,000 files or emails per hour — sustaining the operation over hours or even days to avoid triggering volume-based alerts. The attackers also rotate infrastructure, using separate network connections for sign-in, discovery, and data collection, making correlation harder for defenders.

As Microsoft noted, “Graph abuse rarely appears suspicious when viewed through a single API call.” Only holistic behavioral analysis across multiple events reveals the pattern.

A Parallel Campaign: CEO Fraud at Scale

Microsoft’s disclosure also revealed a related campaign tied to the same threat clusters. Between August 3 and 5, 2026, Storm-3121 sent over one million scam emails impersonating CEOs and requesting fraudulent ACH transfers for fake ServiceNow subscriptions. The emails used AI-generated templates tailored to specific recipients and included forged invoices and email threads. The targeted sectors included IT services, consumer goods, real estate, and manufacturing — all primarily U.S.-based organizations.

The phishing infrastructure for this campaign used domains like service-nowinc[.]com and domainlify[.]net, and demonstrated the same level of pre-attack research that characterizes the passkey phishing campaign: reconnaissance of organizational structures, employee names, and reporting hierarchies drawn from social media and professional networking platforms.

Why Passkey Phishing Matters

The irony is sharp. Passkeys — FIDO2-based credentials bound to a specific device and site — are genuinely phishing-resistant when implemented correctly. The cryptographic handshake ensures that a legitimate passkey cannot be intercepted by a fake login page. But these attackers are not trying to break the cryptography. They are exploiting the transition period — the months or years during which organizations are rolling out passkeys alongside traditional credentials — and the confusion that comes with it.

When employees receive a call saying “we need you to update your passkey settings,” many do not know enough about the technology to recognize that the request makes no sense. The attackers are betting on adoption anxiety: the gap between organizations announcing passkey support and employees actually understanding how passkeys work.

This is a social engineering attack dressed in the language of better security. And it is working.

Who Is Behind It

Microsoft attributes the campaigns to Storm-3121, which has links to the ShinyHunters and Falcon extortion operations, and Storm-3032 (UNC6671), described as a loose-knit cybercrime collective operating under multiple extortion brands. These are not state-sponsored actors — they are financially motivated groups that invest heavily in infrastructure, reconnaissance, and operational security.

The groups have also been observed using compromised Microsoft Teams accounts to send further phishing messages within organizations, leveraging the implicit trust that internal communication platforms carry.

What Defenders Should Do

Microsoft and several security firms have issued specific guidance for organizations that may be targeted:

Detection: Correlate identity logs with Graph API, SharePoint, OneDrive, and Exchange activity. Look specifically for unusual sign-ins followed immediately by new MFA method registrations — this is the clearest signal of a successful AitM attack. Alert on intensive Graph discovery queries and automated high-volume downloads.

Immediate Response: If a compromise is suspected, revoke all active sessions and refresh tokens, reset credentials, and remove any unauthorized authentication methods. Check for and remove rogue mailbox rules that may be forwarding email to external addresses.

Prevention: Restrict cloud access from unmanaged devices. Limit device-code authentication flows to only the scenarios that genuinely require them. Review and tighten application consent policies and privileged Graph API permissions.

User Education: This is perhaps the most critical control. Employees need to understand that legitimate IT departments will never ask them to visit a URL provided via phone or SMS to “fix” a passkey. Any unexpected helpdesk contact should be verified through known internal channels — not through the number or link provided by the caller.

The Bigger Picture

The passkey phishing campaign is a case study in how attackers adapt faster than defenders deploy. Every security improvement creates a new surface for social engineering — not against the technology itself, but against the humans learning to use it. As organizations accelerate their passkey rollouts in 2026 and beyond, security teams need to pair the technical deployment with clear, ongoing user education that specifically addresses the kinds of pretexts attackers are already using.

The technology is sound. The transition is the vulnerability.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.