Hackers Pose as IT Support, Use Fake Passkey Lures to Steal Microsoft 365 Access

Hackers Pose as IT Support, Use Fake Passkey Lures to Steal Microsoft 365 Access

Microsoft warns of fake passkey and IT support attacks targeting Microsoft 365 accounts to steal authentication tokens and access corporate cloud data.

Listen to this article

0:00

Press play to start listening

A new social engineering campaign has been discovered in which attackers are using fake passkeys and IT support requests to gain access to Microsoft 365 accounts. Microsoft Threat Intelligence has been tracking the activity since May 2026 and says the initial-access methods are being used by several threat actors, including Storm-3121 and Storm-3032.

The company links Storm-3121 activity to ShinyHunters and Falcon extortion, while Storm-3032 represents actors that split from BlackFile and now operate under the Helix extortion banner.

Passkey Lures Target Corporate Employees

The attackers begin by researching potential targets through social media and professional networking sites. They contact employees by phone, text, or Microsoft Teams. In some cases, the messages come from compromised accounts, making them appear to be from a familiar contact. Posing as IT support, the attackers say the employee needs to update a passkey, single sign-on (SSO), or multi-factor authentication (MFA).

The victims are then sent to fake Microsoft sign-in pages. Microsoft found domains including passkeyhelpdesk.com, integratedsso.com, and oktasession.com, along with URLs that include the target company’s name, such as contoso.add-passkey.com. Some domains were registered through Nicenic, although Microsoft cautions that registration alone does not indicate registrar involvement.

The passkey theme is primarily a social engineering pretext rather than an attack on passkey cryptography. Microsoft found that victims were instead directed through adversary-in-the-middle (AiTM) phishing or device-code authentication flows.

In AiTM attacks, attackers can capture credentials and session tokens. With device-code phishing, victims enter a code on Microsoft’s legitimate authentication page and unknowingly authorize an attacker-controlled client to obtain access.

Persistence and Cloud Data Collection

After compromising an account, the attackers register additional authentication methods under their control, such as an authenticator app, phone number, or software-based OTP token. This gives them another route back into the account even if the original access method is disrupted.

The attackers also use Node.js-based tooling and Microsoft Graph APIs to enumerate users, groups, permissions, applications, and other organizational resources before accessing SharePoint Online, OneDrive for Business and, in some cases, Exchange Online for files, emails and attachments.

Microsoft also saw large volumes of activity against SharePoint and OneDrive linked to the python-httpx user agent. The user agent alone is not evidence of malicious activity, but the activity becomes more suspicious when combined with unusual sign-ins, authentication-method changes, reconnaissance, and large-scale data access.

The collection was generally measured rather than a rapid “smash-and-grab,” with fewer than 1,000 files or emails accessed within an hour in observed cases. Microsoft said this pace could help the activity blend with normal enterprise usage while enabling sustained collection.

Attack Sequence (Source: Microsoft)

Protection Strategies

Microsoft recommends investigating unusual sign-ins together with newly registered authentication methods, Microsoft Graph reconnaissance, token activity, abnormal SharePoint or OneDrive downloads, and suspicious mailbox access. For confirmed compromises, organizations should revoke active sessions and remove unauthorized authentication methods.

Organizations can reduce the risk by using phishing-resistant MFA, including FIDO2 passkeys or hardware-backed security keys, blocking device-code authentication where it is not required, and limiting access from unmanaged devices.

Microsoft recommends phishing-resistant authentication such as passkeys as part of the defence against these attacks. The campaign does not demonstrate a weakness in passkey cryptography itself; attackers are using passkey enrollment as a convincing reason to steer employees into other authentication flows.

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts