threat_intelligence1033 wordsRead on Arc Codex

Passkey phishing attacks: Why Microsoft 365 security can't stop at sign

Passkey phishing attacks: Why Microsoft 365 security can't stop at sign-in Passkey-themed phishing attacks are being used to compromise Microsoft 365 accounts. Here’s why organizations need identity protection, account takeover detection, and post-sign-in visibility to stop attackers after initial access. Key takeaways - Passkeys remain strong, but attackers are using passkey-related messages as social engineering lures. - The real risk begins after attackers gain access to a trusted Microsoft 365 account. - Security teams need visibility across identity, email, cloud apps, and data activity. - Account takeover detection and post-delivery remediation are critical when prevention fails. Passkeys are designed to make phishing attacks harder. So, when attackers started using passkeys as the lure, it got a lot of people’s attention. Passkey phishing is a social engineering tactic where attackers use passkey, MFA, or single sign-on updates as a lure to trick users into granting access or changing authentication settings. According to recent research from Microsoft Security Research, threat actors have been impersonating IT help desk staff and contacting employees directly through phone calls and text messages. The message is simple: Your passkey, MFA, or single sign-on settings need updating. Follow these instructions now or risk losing access. It sounds routine. That's exactly why it works. And once a user takes the bait, things can escalate quickly. What happens after a passkey phishing attack succeeds? The first thing that stands out in Microsoft’s investigation is that the attackers weren’t really interested in passkeys. Passkeys were just the hook. The real goal was access to Microsoft 365 accounts. Once they had that, the campaign looked very different from a traditional phishing attack. The attackers added authentication methods they controlled. They explored the Microsoft 365 environment. They identified valuable information. Then they started collecting it. In some cases, that activity continued for days. That’s what makes this campaign important. The compromise wasn’t the event. It was the beginning. Why do attackers focus on persistence after Microsoft 365 compromise? One detail appears repeatedly throughout Microsoft’s findings: The attackers weren’t rushing. After gaining access, they focused on persistence. New authentication methods were registered, allowing them to maintain control and continue operating inside the environment. From there, they gradually mapped the organization. Who has access to what? Where is valuable information stored? Which accounts could be useful next? Those answers don’t come from a quick smash-and-grab attack. They come from spending time inside the environment. And that's exactly what these attackers were trying to buy themselves. Why is account takeover activity hard to detect? This is where things become difficult for defenders. Microsoft observed attackers using Microsoft Graph, SharePoint, OneDrive, Exchange Online, and other legitimate Microsoft 365 services. None of those activities is unusual on its own. Employees search for files. They access SharePoint. They read email. They use business applications. On the surface, much of the attacker activity looked exactly the same. The danger only became clear when those events were connected together. A successful sign-in was followed by MFA changes. The MFA changes were followed by tenant reconnaissance. Reconnaissance was followed by mailbox access and file collection. Viewed individually, these events appeared normal. Viewed together, they revealed an attack progressing through the environment. Why is identity compromise a cloud security incident? For years, email security conversations focused on keeping malicious messages out of inboxes. That’s still important, but attacks like this highlight a much bigger challenge. Once attackers gain access to a Microsoft 365 identity, they’re no longer targeting just email. They’re targeting collaboration tools, cloud storage, internal communications, business processes, and organizational knowledge. At that point, you’re dealing with much more than a phishing event. You're dealing with a cloud security incident. Security becomes a different problem after authentication Microsoft’s research reinforces something many security teams are already seeing in practice. Strong identity controls remain essential. Technologies such as passkeys, Microsoft Entra, Conditional Access, Microsoft Defender, and Exchange Online Protection provide a strong foundation for securing Microsoft 365 environments. But the challenge changes after authentication. The important questions become: Has a compromised account started sending suspicious messages? Has a new authentication method been added? Is unusual mailbox activity occurring? Has someone started quietly collecting files from SharePoint or OneDrive? These are the signals that often emerge later in the attack lifecycle. They’re also why many organizations are placing greater emphasis on account takeover detection, continuous remediation, and post-delivery security alongside traditional prevention controls. The goal isn’t simply blocking threats at the front door. It’s understanding what happens if one gets through. How can security teams detect post-sign-in attacks? Perhaps the most important lesson from this campaign is that nobody would have understood the attack by looking at a single event. Not the sign-in. Not the MFA registration. Not the mailbox activity. Not the SharePoint access. Not the Microsoft Graph requests. Microsoft specifically noted that Graph activity should be assessed through behavioral progression and cross-event correlation rather than individual requests in isolation. That observation applies well beyond this campaign. Modern attacks rarely stay in one place. They move across identities, mailboxes, applications, cloud services, and data. The challenge is connecting those signals before an attacker has time to achieve their objective. What should organizations learn from passkey phishing attacks? It would be easy to read this story and conclude that it’s about passkeys. It’s not. Passkeys remain one of the strongest authentication technologies available. The bigger lesson is that attackers continue to look for ways around security controls by exploiting something much harder to defend than technology: trust. And once they’re in, they’re often patient. For organizations using Microsoft 365, strong identity controls are only part of the equation. Attacks like this highlight the importance of spotting compromised accounts quickly, continuously remediating emerging threats, and connecting activity across identities, email, cloud services, and data. Because the real risk isn’t the initial compromise. It’s everything that happens afterwards. 2026 Email Threats Report Learn how AI and phishing-as-a-service are reshaping the email threat landscape and how to stay protected Subscribe to the Barracuda Blog. Sign up to receive threat spotlights, industry commentary, and more. The Managed XDR Global Threat Report Key findings about the tactics attackers use to target organizations and the security weak spots they try to exploit

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.