Microsoft has reported active passkey phishing campaigns using fake help-desk calls and texts to trick staff into 'updating' passkey or SSO settings, opening a route past MFA into Microsoft 365. For UK IT buyers, it's a reminder that phishing-resistant MFA and passkeys still depend entirely on how they're rolled out.
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| Campaign activity begins | 0 | 6 |
| Fake Entra passkey… | 8 | 2 |
| Two campaigns disclosed by… | 16 | 2 |
What Microsoft's report revealed, as covered 13 September 2026
In a report covered on 13 September 2026, Microsoft describes attackers abusing passkey-themed social engineering to compromise Microsoft accounts and steal data from Microsoft 365 services. Victims receive calls or texts impersonating IT or help-desk staff, pushing them to "update" passkey, MFA or SSO settings.
The lure typically arrives by SMS to a personal device and directs victims to a counterfeit Microsoft sign-in page. From there, attackers steer the session into an adversary-in-the-middle (AitM) or device-code authentication flow, letting them capture credentials or complete sign-in on the victim's behalf. Microsoft links the activity to ShinyHunters, Helix and other extortion gangs.
Why this matters for UK enterprise MFA strategy
For years, UK security teams have been told passkeys and phishing-resistant MFA are the fix for credential theft. That's still broadly true at the protocol level — but this campaign doesn't break passkey cryptography, it targets the enrollment and helpdesk workflow around it. If a threat actor can talk, text or trick a user into registering the attacker's own passkey or approving a device-code prompt, the strong authentication itself becomes irrelevant.
This is a governance and process failure as much as a technical one. Buyers evaluating Identity and Access Management solutions should be asking vendors specifically how passkey enrollment, re-enrollment and help-desk identity verification are locked down, not just whether passkeys are supported.
The July precedent: fake Entra passkey enrollment
A closely related campaign reported on 10 July 2026 showed the same logic in a more targeted form. A threat actor tracked by Okta as O-UNC-066 used voice-based fake security requests to prompt Microsoft 365 users to enrol a new Entra passkey — then registered its own passkey against the victim's account, gaining unauthorized access without ever needing the original password.
That July campaign was tied to data extortion rather than opportunistic credential theft, and it specifically mirrored Microsoft's genuine passkey enrollment flow closely enough to pass casual scrutiny. BleepingComputer reports this style of activity has been observed since at least May 2026, targeting corporate Microsoft accounts and Microsoft 365 data rather than consumer accounts.

Spotting the infrastructure: domains and delivery patterns
BleepingComputer's report lists a recognisable pattern of lure domains used in these campaigns, including passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, oktasession[.]com, keysyncos[.]com and oskeysync[.]com — an example set drawn from Microsoft and partner threat intel, not necessarily an exhaustive list. These domains are described in reporting as attacker-controlled, not official Microsoft or Okta properties, and are designed to resemble legitimate identity or SSO support sites.
For UK security operations teams, this is directly actionable: these domain patterns and naming conventions can be fed into email and DNS filtering, and staff awareness material can reference the actual lure style rather than a generic "phishing email" warning. Teams running managed detection & response should confirm these indicators are already in active blocklists.
What UK buyers should change now
No CVE has been assigned to this activity — it's a social engineering and process abuse issue, not a software vulnerability, which means patching alone will not close the gap. The fix sits in three places: help-desk identity verification, passkey/MFA enrollment controls, and user awareness of AitM and device-code flows specifically.
Buyers should push vendors and internal teams to restrict who can approve new passkey or MFA device enrollments, ideally requiring an out-of-band, verified channel rather than a phone call or SMS link. Organisations still relying on legacy or partially deployed conditional access should treat this as fresh justification to implement a Zero Trust security model where every enrollment event is independently verified, not just authenticated.
- •Lock down help-desk and IT support identity verification before allowing any passkey/MFA change
- •Disable or tightly restrict device-code authentication flows where not operationally required
- •Train staff to recognise SSO/passkey "update" lures delivered via personal-device SMS or calls
- •Review Microsoft 365 backup posture in case extortion-linked actors reach mailbox or SharePoint data
Practical next steps for security and IT leaders
Because these campaigns are explicitly linked to extortion gangs rather than pure credential harvesting, UK buyers should also revisit data resilience, not just access control. If an attacker reaches a compromised Microsoft 365 account, the ability to isolate, restore and audit tenant data quickly limits the blast radius — which is why it's worth being able to compare Microsoft 365 backup solutions alongside any identity hardening project.
Equally, since the initial lure typically arrives via email or SMS impersonating IT support, tightening inbound filtering and sender verification helps stop the chain before it reaches the fake sign-in page. Organisations without a recent review should enhance your email security controls and consider bringing in a specialist to choose a Managed Security Service Provider if internal capacity to monitor this evolving threat is limited.
- 01The Hacker News — Attackers Use Passkey Phishing to Compromise Microsoft 365 Accounts · 13 September 2026
- 02The Hacker News — Hackers Use Fake Microsoft Entra Passkey Enrollment · 10 July 2026
- 03BleepingComputer — Passkey-Themed Phishing Attacks Lead to Microsoft 365 Data Theft · 13 September 2026
- 04thehackernews.com
- 05thehackernews.com
- 06thehackernews.com
- 07thehackernews.com
- 08thehackernews.com
