
Passkey-Themed AitM Attacks Compromise Microsoft 365 Identities via SMS Lures Since May 2026
Passkey phishing via AitM and device-code flows has enabled sustained Microsoft 365 compromises with automated data collection since May 2026. Evidence shows heavy pre-attack OSINT and proxy infrastructure use that evades standard MFA. The campaigns link financial fraud lures with identity persistence tactics, indicating maturing operational tradecraft.
The second campaign, active since May 2026, begins with targeted calls or SMS messages impersonating IT support to prompt immediate passkey or MFA updates. Victims are directed to counterfeit Microsoft login pages that capture session tokens or force device-code consent, granting persistent access. Post-compromise activity includes rapid addition of attacker MFA methods, followed by automated Graph API queries and high-volume downloads from OneDrive and SharePoint. Pre-attack reconnaissance draws from public LinkedIn and corporate directories to personalize lures and select targets with elevated privileges. Microsoft's reporting aligns with observed patterns in prior AitM campaigns against Entra ID, where proxy infrastructure masked traffic. The technique exploits user trust in passkey prompts, bypassing traditional phishing filters since no credential is directly entered. Independent telemetry from endpoint vendors shows similar SMS-based redirects increasing in finance and manufacturing sectors, matching the domains and timing described. The first campaign's CEO impersonation for ACH fraud using ServiceNow branding demonstrates layered narrative attacks that reduce skepticism through fabricated threads. Over one million emails in three days indicate scaled infrastructure abuse of legitimate delivery services. These operations reveal a shift toward identity-layer persistence rather than initial access brokers. Next steps include expanded monitoring of personal phone number exposure in corporate directories and enforcement of hardware-bound passkeys that resist proxy capture. Organizations should audit recent consent grants and Graph activity baselines immediately.
Microsoft: Passkey-themed SMS lures targeting Entra ID will exceed 5000 unique incidents by December 2026
Sources (2)
- [1]Primary Source(https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html)
- [2]Supporting Source(https://www.microsoft.com/en-us/security/blog/2026/09/microsoft-threat-intelligence-passkey-campaigns/)