Social Engineering Campaign Hijacks Microsoft 365 Accounts via Passkey Alerts

Social Engineering Campaign Hijacks Microsoft 365 Accounts via Passkey Alerts

First seen 10 Sep 2026, 10:43 UTC Blogs.Microsoftattack.mitre.orgGbhackersRedpacketsecuritylearn.microsoft.com 71.0

Article Content

Browse articles
ThreatCluster

A social engineering campaign impersonating IT support staff is actively hijacking Microsoft 365 accounts. The attackers use passkey-themed lures to trick users into providing credentials, leading to unauthorized access and data exfiltration. Microsoft Security Research has tracked these intrusions since May 2026, observing unusual sign-ins, added authentication methods, and extensive data collection from SharePoint, OneDrive, and Exchange Online. The attack method involves adversary-in-the-middle phishing and device-code authentication flows. Victims are often contacted via phone or SMS, creating a sense of urgency to act. The campaign has affected multiple organizations, with ongoing investigations into the extent of the breaches. Defenders are advised to monitor Microsoft Graph, SharePoint, and Exchange signals for suspicious activity and revoke unauthorized authentication methods.

Key Points: • Attackers impersonate IT staff to hijack Microsoft 365 accounts. • Campaign has been active since May 2026, targeting multiple organizations. • Defenders should monitor Microsoft services for unusual activity.

Ask AI about this cluster

Timeline

2026-05-01
Campaign began
Social engineering attacks targeting Microsoft 365 accounts started using passkey lures.
Blogs.Microsoft
2026-09-09
Microsoft reports ongoing intrusions
Microsoft Security Research confirms tracking of cloud-based intrusions with unusual sign-ins and data collection activities.
Blogs.Microsoft
2026-09-10
Redpacketsecurity publishes details
Redpacketsecurity corroborates Microsoft's findings, detailing the attack chain and methods used by threat actors.
Redpacketsecurity
2026-09-10
Gbhackers reports on the campaign
Gbhackers highlights the impersonation tactics and data collection from Microsoft 365 services.
Gbhackers