Passkey-Themed Phishing Campaign Targeting Microsoft 365 Accounts
First seen Sep 12, 2026 · Updated Sep 12, 2026
Threat actors linked to ShinyHunters, Helix, and other extortion groups are conducting social engineering campaigns that abuse passkey and single sign-on registration flows to compromise corporate Microsoft 365 accounts. Stolen credentials and session data are used to exfiltrate sensitive organizational data for extortion purposes.
Technical Analysis
Attackers impersonate IT support or SSO/passkey enrollment prompts to trick users into authorizing malicious passkey registrations or divulging authentication codes, effectively bypassing traditional MFA protections by abusing trust in passwordless authentication UX. Once account access is obtained, attackers leverage legitimate Microsoft 365 session tokens and OAuth grants to access mailboxes, SharePoint, and Teams data, often exfiltrating data via Graph API calls to avoid detection. The campaign mirrors known ShinyHunters/Scattered Spider tactics of help-desk impersonation and MFA fatigue, now adapted to newer passwordless authentication mechanisms. Organizations using Microsoft 365 integrations for AI agent workflows (e.g., Copilot, Graph API-connected RAG pipelines, or agent frameworks with stored OAuth tokens) face elevated risk, as compromised credentials or session tokens could allow attackers to exfiltrate data accessible to those agents or hijack agent-to-service authentication paths.
Affected Systems
Microsoft 365 (Exchange Online, SharePoint, Teams), Entra ID (Azure AD) passkey/FIDO2 and SSO enrollment flows, corporate identity federation configurations
Indicators of Compromise
- Phishing domains impersonating Microsoft SSO/passkey enrollment pages (specific domains not disclosed in source)
- Fraudulent IT helpdesk emails referencing passkey setup
- Anomalous OAuth app consent grants in Entra ID audit logs
- Unusual Microsoft Graph API data exfiltration patterns
Remediation Steps
- 1
Enforce phishing-resistant authentication policies
Restrict passkey/FIDO2 enrollment to managed devices and require verification through a secondary trusted channel before allowing new passkey registrations.
- 2
Audit Entra ID sign-in and consent logs
Review conditional access and OAuth application consent logs for anomalous SSO enrollments, new device registrations, or unusual application permissions granted to user accounts.
- 3
Train staff on help-desk impersonation tactics
Educate employees and IT support staff to verify identity through out-of-band channels before assisting with passkey resets or SSO account changes.
- 4
Monitor Microsoft Graph API activity
Deploy detection rules for abnormal Graph API calls, bulk mailbox/file access, and data exfiltration patterns tied to compromised accounts, including those used by AI agents or automation pipelines with Microsoft 365 access.
- 5
Rotate and scope down OAuth tokens/API keys
Revoke and reissue OAuth tokens and application credentials used by agents or integrations connected to Microsoft 365, applying least-privilege scopes.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.