Start with Identity
← Blog
News

Attackers are phoning employees about their passkeys, then enrolling their own MFA method

Microsoft detailed a campaign running since May 2026 in which callers posing as IT tell US enterprise users to update their passkey or MFA settings, route them to a fake sign-in page, then add their own authentication method for persistence.

By SWI Community TeamSep 13, 2026Updated Sep 14, 2026

Microsoft disclosed a campaign active since May 2026 that targets US enterprise users in IT services, consumer goods, real estate, and discrete manufacturing. Attackers research a target's employer, job title, and personal phone number from social media and professional networks, then call or message that personal number posing as the organization's IT help desk, warning that the user must immediately update their passkey, MFA, or SSO configuration to avoid losing access. An SMS to the personal device carries a link to a counterfeit Microsoft sign-in page. After the hijack, Microsoft observed unusual sign-ins followed by the attacker registering new authentication methods, Microsoft Graph queries, and bulk downloads from SharePoint, OneDrive, and email. Microsoft disclosed it alongside a separate CEO-impersonation fraud campaign that sent over a million emails between August 3 and 5, 2026.

Why it matters

Nothing about passkeys is broken here. The passkey is the pretext. The attacker needs a plausible reason for an employee to visit a sign-in page on a personal phone, and "your passkey needs updating" is currently the most plausible reason available, precisely because so many organizations really are migrating and really are sending employees such notices.

That is the cost of a migration nobody warned users about in advance. A workforce that has been told to expect authentication changes is a workforce primed to comply with one. Any organization rolling out passkeys should be telling people now, in concrete terms, how it will and will not contact them: never by SMS to a personal number, never with a link, always through a channel the user initiates.

The persistence step is the one to hunt for. Registering an attacker-controlled authentication method survives the password reset, the session revocation, and usually the incident closure, which is the same failure we flagged in Issue 7. Alert on every new MFA or passkey registration, treat registrations that follow an anomalous sign-in as an incident by default, and enumerate authentication methods as a standard step in account recovery. The technique is help desk social engineering pointed at the employee rather than the help desk.

Source: The Hacker News

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.