Or…yah know…just implement basic O365/Teams hardening and fix the root cause? 🤷🏼♂️
Hackers are using passkeys as bait to steal Microsoft 365 accounts.
Passkeys were supposed to replace passwords and kill phishing.
How it works:
The setup:
Attackers research the target organization first. LinkedIn. job postings. their Microsoft tenant configuration. they know the employee's name, their team, and who their IT helpdesk is.
then they call. or text. or message on Teams.
they impersonate IT support. the message is urgent: your passkey, MFA, or SSO settings need an immediate update or you'll lose access to corporate systems. click this link to complete enrollment.
why it works:
passkeys are new. most employees have never set one up before. they don't know what a legitimate passkey enrollment looks like. the phishing kit mimics the exact system dialog they'd expect to see.
the campaign began in April 2026. the groups behind it: ShinyHunters, Helix, and LAPSUS$ affiliates, the same collective responsible for some of the largest corporate breaches of the last three years.
once inside they spread exfiltration over hours or days. access fewer than 10 files per session to blend with normal usage. harvest SharePoint, OneDrive, and email. then post samples on a data leak site and give you 72 hours to pay.
What a legitimate IT request never does:
— create urgency about losing access
— send you a link via SMS to your personal phone
— ask you to enter a code they give you over the phone
— ask you to approve an MFA prompt you didn't initiate
— ask you to do any of this right now, without giving you time to verify
if any of those happen: hang up. call IT directly using a number you already have.