Cybercriminals have launched a sophisticated phishing campaign targeting Microsoft 365 accounts by exploiting passkey-themed social engineering tactics. This attack method effectively bypasses multi-factor authentication, allowing hackers to take over accounts and exfiltrate cloud-stored data. The attackers initiate contact through calls and text messages, impersonating IT support and misleading employees into visiting fraudulent sign-in pages that mimic legitimate ones.

Once an account is compromised, it can be used to propagate phishing lures via Microsoft Teams. Microsoft's researchers have observed these activities in numerous cloud intrusions since May 2026. The attack pattern typically involves unusual sign-ins, the introduction of new authentication methods, and extensive queries and downloads from services like SharePoint, OneDrive, and email. These actions indicate a calculated effort to gather data from compromised accounts.

The attackers employ a tactic known as adversary-in-the-middle phishing, where a fake site intercepts the victim's credentials and session tokens as they are relayed to the genuine service. Victims may also be tricked into completing a device-code sign-in that grants the attackers access. Even after multi-factor authentication is completed, the attackers can maintain session control.

In some instances, after gaining access, attackers aim to establish persistent access by adding their own authentication methods such as phone numbers or software tokens. This persistence can be difficult to remove, as a simple password reset may not suffice if active sessions and rogue authentication methods remain in place.

To mitigate the risk, organizations should scrutinize unusual sign-ins and newly registered authentication factors. Employees are advised to verify unexpected IT support requests through known internal channels, avoiding any contact information provided by the caller. Once attackers gain persistence, they can explore the victim's accessible resources using Microsoft Graph, conducting high-volume file access and downloads from SharePoint, OneDrive, and even Exchange Online. The attack strategy often involves maintaining a low profile to avoid detection while continuously extracting data over extended periods.

Defenders are encouraged to correlate identity and access records across various platforms, focusing on signals such as unusual sign-ins, intensive Graph activity, and unauthorized downloads. Upon confirming a compromise, it is crucial to revoke active sessions, reset credentials, and remove unauthorized authentication methods. Implementing phishing-resistant multi-factor authentication and restricting access from unmanaged devices can further enhance security. Training employees to recognize scams across multiple communication channels is also essential in preventing these attacks.