Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Microsoft reports passkey-themed phishing campaigns hijacking Microsoft 365 accounts via AiTM and device-code flows, then exfiltrating cloud data.
Microsoft researchers identified passkey-themed phishing across cloud intrusions observed since May 2026, where callers posing as IT support direct victims to lookalike sign-in pages. The flows include adversary-in-the-middle phishing and device-code authentication, letting attackers capture usable sessions even when MFA succeeds, followed by rogue MFA registration for persistence. Attackers enumerate tenants via Microsoft Graph and collect SharePoint, OneDrive, and Exchange data at rates below 1,000 items per hour; lure domains include passkeyhelpdesk.com and setupmypasskey.com.
- The passkey narrative is a pretext for AiTM phishing or device-code sign-ins that capture sessions despite MFA.
- Attackers add their own authenticator apps, phone numbers, or OTP tokens for durable persistence.
- Graph enumeration and high-volume cloud downloads use python-httpx and rotate infrastructure to blend in.
- Recommended: phishing-resistant MFA, session and token revocation, and review of newly registered authentication methods.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | add-passkey.com | y security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain |
| domain | integratedsso.com | ey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session Do |
| domain | keysyncos.com | O Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchroniz |
| domain | myconnectkey.com | istration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection D |
| domain | oktasession.com | om Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key sync |
| domain | oskeyconnect.com | hronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account val |
| domain | oskeyregister.com | ey synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronizati |
| domain | oskeysetup.com | onization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration Dom |
| domain | oskeysync.com | r session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup Dom |
| domain | passkeyhelpdesk.com | m becoming a data breach. Type Indicator Description Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com Passkey |
| domain | portalsetuphub.com | validationsetupac[.]com Account validation and setup Domain portalsetuphub[.]com Portal setup Note: IP addresses and domains are intention |
| domain | secure-passkey.com | on Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setu |
| domain | setupmypasskey.com | rt lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollment |
| domain | syncmykey.com | ey setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connect |
| domain | validationsetupac.com | connection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account validation and setup Domain portalsetuphub[.]com |
Full article817 words · extracted from cybersecuritynews.com · click to collapse
Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. It can defeat MFA protections.
The campaign starts with calls and texts to employees. Attackers pose as IT support, claim a passkey, MFA, or single sign-on setting needs attention, and direct targets to lookalike sign-in pages.
Compromised accounts can also send lures through Microsoft Teams. Microsoft researchers identified the activity across cloud intrusions observed since May 2026.
They found unusual sign-ins followed by new authentication methods, Microsoft Graph queries, and downloads from SharePoint, OneDrive, and email services. The pattern indicates deliberate collection from compromised cloud identities.
Microsoft said in a report shared with Cyber Security News (CSN) that the attackers rotate infrastructure and may use separate connections for sign-in, discovery, and collection. This can resemble normal use while attackers map organizations and take files or messages.
Hackers Use Passkey-Themed Phishing
The passkey story is a pretext, not an effort to enroll a passkey. Victims can be put into an adversary-in-the-middle phishing flow, where a fake site relays their sign-in to the real service and captures credentials and session tokens.
They may instead complete a device-code sign-in that grants access to an attacker-controlled client. A user can complete MFA and still surrender a usable cloud session.
A BigBear session theft campaign showed phishing pages can steal proof that MFA was completed. Authentication prompts deserve the same scrutiny as password requests, after an unexpected call or text.
In one sequence, an attacker signed in from an unmanaged device, then opened account portals with the same session.
In another, device-code approval produced a token replayed to bypass MFA. Researchers also saw attackers return using compromised credentials paired with an authenticator method registered earlier.
After entry, operators seek lasting access by adding a phone number, authenticator application, or software one-time-password token under their control. A password reset may not evict them if active sessions, refresh tokens, or rogue authentication methods remain. Teams should investigate risky sign-ins alongside every newly registered factor.
Organizations have faced Entra passkey enrollment attacks using phone impersonation. Employees should confirm unexpected helpdesk requests through a known internal channel, never a number or link given by the caller. A verified reporting route for authentication requests can stop the attack before access is granted.
From Account Access to Cloud Collection
Once persistence is established, the attackers use Microsoft Graph to learn what the user can reach. They enumerate users, groups, roles, applications, permissions, sites, drives, folders, files, mailboxes, and attachments. One request may be normal, but broad discovery followed by content retrieval reveals a coordinated intrusion.
The operators then target SharePoint Online and OneDrive for Business with high-volume file access and downloads. Some cases extended to Exchange Online REST API access to email content. Microsoft observed collection often below 1,000 files or emails per hour, a pace that can avoid attention while continuing for hours or days.
This resembles device code phishing abuse, in which a legitimate approval page is abused to gain access without taking a browser cookie. The damage follows when criminals search repositories and collect accessible data.
Defenders should correlate identity, Graph, SharePoint, OneDrive, and Exchange records, rather than treating an IP address or domain as conclusive. Important signals include an unusual sign-in followed by MFA enrollment, intensive Graph discovery, anonymous-proxy access, automated downloading, and concentrated mailbox or attachment searches.
For a confirmed compromise, teams should revoke active sessions and refresh tokens, reset credentials, remove unauthorized authentication methods and mailbox rules, then require secure MFA registration. They should require phishing-resistant MFA, limit cloud access from unmanaged devices, restrict device-code flows unless needed, and review application consent plus privileged Graph permissions.
The actions reflect lessons from M365 session hijacking cases, where stolen sessions may survive a password reset. Training should cover voice, text, and Teams scams, while cloud and mailbox auditing can prevent a routine-looking passkey update from becoming a data breach.
| Type | Indicator | Description |
|---|---|---|
| Domain | passkeyhelpdesk[.]com | Passkey support lure |
| Domain | secure-passkey[.]com | Passkey security |
| Domain | setupmypasskey[.]com | Passkey setup |
| Domain | add-passkey[.]com | Passkey enrollment |
| Domain | integratedsso[.]com | SSO |
| Domain | oktasession[.]com | Identity-provider session |
| Domain | keysyncos[.]com | Key synchronization |
| Domain | oskeysync[.]com | Key synchronization |
| Domain | oskeysetup[.]com | Key setup |
| Domain | oskeyregister[.]com | Key registration |
| Domain | syncmykey[.]com | Key synchronization |
| Domain | myconnectkey[.]com | Key connection |
| Domain | oskeyconnect[.]com | Key connection |
| Domain | validationsetupac[.]com | Account validation and setup |
| Domain | portalsetuphub[.]com | Portal setup |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/passkey-themed-phishing/