News and Knowledge Portal for Identity Verification Professionals

collapse
...
Home / Fraud / Passkey enrolment pretext leads to a spike in Microsoft social engineering attacks
Passkey enrolment pretext leads to a spike in Microsoft social engineering attacks

Passkey enrolment pretext leads to a spike in Microsoft social engineering attacks

2026-09-14  Ian Fleming

The activity employed social engineering and and impersonation techniques persistently throughout the authentication phase and was consistent with targeted data capture from compromised cloud infrastructure. The persistence of data and content discovery warranted investigation from Microsoft. To provide an overview of the attack sequence, Microsoft observed the identity compromises from the initial identification of target organisations to vishing and taking control of the victim’s identity. When the session was compromised, attackers could gain access to the personal sign-ins security portal and input the attacker’s manipulated authentication information. A high volume of data was collected and extracted. An attack typically begins with a call from an unknown number claiming to be from someone working at Microsoft’s IT desktop, which guides the unassuming user through a single sign-on (SSO) or MFA reconfiguration to deviate from the real trap: adversary-in-the-middle (AiTM) phishing or device-code authentication flows. In this scenario, the actor can compromise session data and credentials.


Share: