Cybersecurity

Fake IT Helpdesk Calls Defeat Passkey Logins, Microsoft Says

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

Fake IT Helpdesk Calls Defeat Passkey Logins, Microsoft Says
Photo: Coolcaesar / Wikimedia Commons (CC BY-SA 4.0)
0 0
XWhatsAppTelegramLinkedIn

The call sounds routine: someone from IT needs you to finish setting up your passkey, and it is urgent. In a report published on September 9, Microsoft Security Research describes that call as the opening move in a run of cloud intrusions it says it has been tracking since May 2026.

According to Microsoft, attackers reach employees by phone, then send a link — often by SMS to a personal mobile number — to a page that, in Microsoft's words, "closely resembles a legitimate Microsoft sign-in experience." Some links arrive instead as Teams messages from colleagues whose accounts have already been taken over, and Microsoft says the operators stand up domains on patterns such as company-name.integratedsso[.]com.

The passkey framing is largely a story the caller tells. "Despite the frequent use of passkey-themed lures, passkey enrollment is often not the actor's true objective," Microsoft writes. What the fake page actually runs is adversary-in-the-middle phishing or a device-code authentication flow, both of which hand the attacker a working session rather than a password. Microsoft says the operators research their targets first, "likely gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms."

That matters because passkeys and multi-factor prompts are widely sold as phishing-resistant, and cryptographically they are. Microsoft's account points at the step around them: the human being talked through an approval. Once inside, Microsoft says attackers make the access permanent by enrolling "an MFA method under their control, typically by registering a new phone number, authenticator application, or software-based one-time password (OTP) token." They then enumerate the tenant through Microsoft Graph — users, groups, permissions, sites, mailbox content — before bulk downloads from SharePoint Online and OneDrive for Business, with some intrusions reaching Exchange Online over REST APIs.

Microsoft attributes the initial-access activity to groups it tracks as Storm-3121, which it links to ShinyHunters and Falcon extortion, and Storm-3032, which it describes as splintered from the BlackFile group and now operating under the Helix extortion banner. Its recommended countermeasures are to enforce phishing-resistant MFA through Conditional Access, revoke active sessions and refresh tokens for any confirmed compromise, turn on Microsoft Graph activity logs and mailbox auditing, and train staff specifically against voice phishing aimed at MFA enrollment.

Separately — and Microsoft presents it as a distinct campaign, not part of this one — The Hacker News reported on September 13 that Microsoft also disclosed more than one million fraudulent emails sent between August 3 and 5, 2026, in which senders impersonated CEOs to request ACH transfers for fake ServiceNow subscriptions, mainly at U.S. companies in IT services, consumer goods, real estate and discrete manufacturing.

What Microsoft has not said is how big the passkey campaign is. The report names no victim organizations and gives no count of compromised accounts, so the open question is whether the tactic stays with the handful of extortion crews named here or becomes a standard way around MFA.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.