TL;DR: Microsoft disclosed a campaign that tricks users into updating their passkeys after a fake IT call, then sends them to lookalike Microsoft login pages that capture access. Attackers then pull files from SharePoint, OneDrive and Exchange. Phishing-resistant sign-in helps, but only if you also refuse to complete sign-ins that a caller is guiding you through.
Passkeys were designed to make stolen passwords useless, so attackers changed tactics. Reporting from The Hacker News (September 13, 2026) and TechRadar describes Microsoft's findings on passkey-themed social engineering that leads to cloud account takeover.
How the attack works
- A caller pretends to be from your IT or help desk and says your passkey needs updating.
- You are sent to a site that mimics the Microsoft login and acts as a man-in-the-middle, capturing the sign-in.
- With access, attackers pull files from SharePoint, OneDrive and Exchange.
Why it works
The weak point is the person on the phone, not the passkey. A stranger guiding you through a sign-in is the warning sign, whichever authentication method you use.
Rules that stop it
- Real IT will not ask you to complete a sign-in while they stay on an unsolicited call. Hang up and contact IT through the number in your company directory.
- Type the Microsoft address yourself instead of following a link from a call, text or email.
- Report the call to your security team, since attackers usually try several people at once.
- Personal users: apply the same rule to your bank, email provider and carrier. See our remote access scam recovery guide if you already let someone in.
Where passkeys still help
Passkeys remain far better than reused passwords, and our guide to setting up passkeys and authenticator apps still applies. The point is to pair them with the habit of never letting a caller drive.
The AI-assisted side of this is covered in the first AI-agent data breach reported in Spain.
FAQs
Are passkeys still safe to use?
Yes, they are much stronger than reused passwords. The attack described here works by tricking people into completing a sign-in for an attacker, not by breaking the passkey itself.
How do I tell a real IT call from a fake one?
Hang up and call IT using a number from your company directory. Real staff will not object to you verifying them.
What should I do if I completed a sign-in during the call?
Tell your security team immediately, change your password, revoke active sessions and review recent file access and forwarding rules.
To see what an impostor could already find about you, check your digital footprint free.
Curious what's already out there? Scan My Shadow checks a phone number and email across 1,500+ sources and sends a clear report — no guesswork, just facts. Start your scan.
Sources
- The Hacker News: Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
- TechRadar: Microsoft Cloud accounts stolen in highly complex impersonation and passkey phishing campaign
