// Blog / News

Scammers are weaponizing passkeys

Share

Passkeys are one of the best security upgrades in years, a login method that is genuinely hard to phish. So of course attackers have found a way to turn the hype against you. Microsoft is warning about an active campaign in which criminals impersonate IT support and use passkey-themed lures to trick employees into handing over access to Microsoft 365 accounts. The irony is sharp: the scam works precisely because passkeys are new and unfamiliar, and people are not yet sure what a legitimate passkey prompt looks like. Here is how it works and how to stop it.

How the scam works

The attackers do not break the passkey technology; they exploit the confusion around it. Posing as your IT help desk, often by calling or texting an employee's personal phone, they claim there is an urgent problem: your passkey, MFA, or single sign-on needs to be updated right now or you will lose access. The panicked employee is steered to a fake Microsoft sign-in page or an authentication flow that the attacker controls. Once the victim goes through it, the attacker gains access and quietly adds their own login method to the account, so they can keep getting back in even after a password change.

What they do once inside

This is not smash-and-grab. After taking over an account, the attackers map out your cloud environment and quietly harvest data from email, SharePoint, and OneDrive, the same patient, data-focused approach behind many recent Microsoft 365 intrusions. Microsoft has linked the activity to known extortion groups, which means the goal is usually your data and your money. It is the latest turn of a familiar screw: social engineering aimed at your logins, dressed in this year's terminology.

How to shut it down

  • Make the ground rule clear: your IT support will never call or text out of the blue demanding you update a passkey or MFA immediately. Urgency plus a login request is the tell.
  • Verify through a known channel. If a "support" message asks you to change security settings, stop and contact IT the normal way, not through the link or number they gave you.
  • Do security changes yourself, from inside the real app or portal you navigated to, never from a link someone sent.
  • Watch for the tell-tale aftermath: an unexpected new sign-in method or MFA device added to an account is a red flag worth checking for.

The bigger point

Passkeys are still worth adopting, they defeat exactly the fake-login-page phishing that plagues passwords. The lesson here is not to distrust passkeys; it is that attackers always target the newest, least-understood thing, and that a well-trained team is the defence no technology replaces. The moment a "help desk" creates urgency around your login, slow down and verify. We help small businesses lock down Microsoft 365 and train their people to spot exactly this.

Sources:The Hacker NewsBleepingComputer

Would your team fall for a fake "update your passkey now" call from IT? We help small businesses lock down Microsoft 365 and train their people to spot login scams, before an account is lost.

Talk to us

Related