Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Fake Passkey Prompts Are Targeting Microsoft 365 Users; Here's What to Check

Дата публикации: 29-09-2026 12:38:08

Microsoft says attackers are using fake passkey, MFA and SSO prompts to compromise cloud identities, add their own authentication methods and access files and email.

Основное содержимое страницы с новостью.

A call from someone claiming to be your company's IT help desk can sound routine: your passkey, MFA or single sign-on setup needs an urgent update, or your access could be disrupted. The request may even arrive just as your organization is genuinely asking employees to register passkeys.

"Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs," Microsoft said in its September 9 research report.

The timing gives the lures an unusually credible cover. Microsoft began rolling out passkeys as the default authentication experience in Entra ID on September 1, automatically enabling the change for users who were still using SMS or voice authentication and prompting them to register a passkey during MFA sign-in.

The Passkey Isn't The Weakness

"Despite the frequent use of passkey-themed lures, passkey enrollment is often not the actor's true objective. Instead, the passkey narrative serves as a convincing pretext to guide victims through adversary-in-the-middle (AiTM) phishing or device-code authentication flows," Microsoft Security Research said.

The initial contact can come through a call or message to a user's personal phone from someone claiming to be internal IT. "The attack often begins with a seemingly routine call or message on a user's personal phone number from someone claiming to be from the organization's IT helpdesk," Microsoft said.

Microsoft also observed attackers directing victims toward adversary-in-the-middle phishing pages or legitimate Microsoft device-code authentication flows. In the latter case, the victim enters a code on Microsoft's real authentication page but unknowingly authorizes an attacker-controlled client.

That means a genuine-looking Microsoft authentication page does not necessarily make the request safe. The question is how the user arrived there and who initiated the request.

What Happens After Access

"Following account compromise, threat actors often register a new authentication method, mobile device, or software-based OTP to establish persistent access to the compromised identity," Microsoft said in its investigation guidance.

The next stage is reconnaissance. Attackers use Microsoft Graph to enumerate users, groups, permissions and applications, then move toward cloud content. Microsoft observed SharePoint and OneDrive access and email collection through REST APIs, with some activity showing the characteristics of automated collection.

This is why checking only for an unfamiliar sign-in can miss part of the problem. An attacker who has added an authentication method may retain access even after the original phishing event is no longer visible.

What To Check Now

If you receive an unexpected request to configure a passkey, MFA or SSO, don't complete it through the caller's link or instructions. Hang up and contact your organization's IT help desk through a number or channel you already trust.

If you may have already complied, check recent sign-ins and your registered authentication methods. Look specifically for an authenticator app, phone number or other MFA method that you did not add yourself. Microsoft recommends investigating unusual sign-ins alongside authentication-method enrollment, Microsoft Graph activity and abnormal SharePoint, OneDrive or Exchange access. For confirmed compromises, its guidance includes revoking active sessions and removing unauthorized authentication methods.

"Microsoft Entra ID is making passkeys the default sign-in experience," Microsoft said, with the rollout beginning September 1, 2026 for users enabled for SMS or voice authentication. A passkey prompt by itself is not evidence that an account has been compromised. Microsoft is legitimately rolling out passkeys across Entra ID, so users may encounter real registration prompts.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks014.3530-09-2026
2US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access015.7830-09-2026
3Prompt injection научилась размножаться через письма, файлы и комментарии к коду01030-09-2026
4Мошенники начали рассылать вирусные файлы под видом бонусов на заправку012.128-09-2026
5Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets09.230-09-2026
6ЦБ: мошенники начали выдавать себя за госслужащих и просить перезвонить09.2528-09-2026
7JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources09.5328-09-2026
8Хакеры проникли один раз, NeedyMantis остаётся надолго. Microsoft раскрыла новый инструмент скрытого доступа014.5530-09-2026
9Аферисты под видом госужащих стали пугать туляков «цифровой доверенностью»01028-09-2026
10Вирус вместо бонусной карты на бензин: мошенники придумали новую аферу010.8929-09-2026

Классификация: Общество. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 8.26. Источник: www.ibtimes.sg.