Microsoft Says Passkey Lures Now Keep Cloud Access Alive

Microsoft says it has been seeing active cloud intrusions since May 2026 that start with passkey-themed social engineering and end with attacker-added authentication methods in Microsoft 365 accounts. The activity spans unusual sign-ins, Microsoft Graph reconnaissance, and collection from SharePoint, OneDrive, and Exchange Online email. The lure is not really about enrolling a passkey. Victims are steered to a Microsoft-looking login page or a device-code flow, where the attacker captures access or gets an approval; once inside, the attacker adds their own authentication method, which can let them log in again after the original session is cut off. That makes password resets and session revocation incomplete if the added method remains in place. For organizations that use Microsoft 365 identity flows, the durable exposure is the account itself and the data it can reach, not just the stolen session. If helpdesk impersonation or SMS lures can reach employees, a one-time phish can turn into standing access across mail and files until the unauthorized method is removed.

Part of the PlainSec briefing for 2026-09-10

Every edition of this story: Microsoft Says Passkey Lures Now Keep Cloud Access Alive

Sources