45
30
45
55
55
30
30
55
57
30
57
30
30
55
57
55
30
30
30
55
30
55
42
60
57
55
30
55
60
30
Attackers use passkey-themed scams to hijack Microsoft 365 accounts
Microsoft tracks ongoing M365 cloud intrusions since May using passkey-themed helpdesk vishing, AiTM phishing, and device-code abuse.
Microsoft Security Research has tracked active cloud intrusions since May in which attackers posing as IT helpdesk staff lured employees with fake passkey/MFA enrollment requests. Attacks used adversary-in-the-middle phishing pages, device-code authentication flows, and Teams messages from compromised accounts. Attackers registered their own MFA methods, enumerated tenants via Microsoft Graph, and accessed SharePoint, OneDrive, and Exchange Online data, throttling activity below 1000 files/emails per hour.
78
60
45
55
30
60
45
57
55
60