Redpacketsecurity
Social Engineering Campaign Hijacks Microsoft 365 Accounts via Passkey Alerts
Article Content
A social engineering campaign impersonating IT support staff is actively hijacking Microsoft 365 accounts. The attackers use passkey-themed lures to trick users into providing credentials, leading to unauthorized access and data exfiltration. Microsoft Security Research has tracked these intrusions since May 2026, observing unusual sign-ins, added authentication methods, and extensive data collection from SharePoint, OneDrive, and Exchange Online. The attack method involves adversary-in-the-middle phishing and device-code authentication flows. Victims are often contacted via phone or SMS, creating a sense of urgency to act. The campaign has affected multiple organizations, with ongoing investigations into the extent of the breaches. Defenders are advised to monitor Microsoft Graph, SharePoint, and Exchange signals for suspicious activity and revoke unauthorized authentication methods.
Key Points: • Attackers impersonate IT staff to hijack Microsoft 365 accounts. • Campaign has been active since May 2026, targeting multiple organizations. • Defenders should monitor Microsoft services for unusual activity.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.