Attackers are phoning employees about their passkeys, then enrolling their own MFA method
Microsoft detailed a campaign running since May 2026 in which callers posing as IT tell US enterprise users to update their passkey or MFA settings, route them to a fake sign-in page, then add their own authentication method for persistence.
Microsoft disclosed a campaign active since May 2026 that targets US enterprise users in IT services, consumer goods, real estate, and discrete manufacturing. Attackers research a target's employer, job title, and personal phone number from social media and professional networks, then call or message that personal number posing as the organization's IT help desk, warning that the user must immediately update their passkey, MFA, or SSO configuration to avoid losing access. An SMS to the personal device carries a link to a counterfeit Microsoft sign-in page. After the hijack, Microsoft observed unusual sign-ins followed by the attacker registering new authentication methods, Microsoft Graph queries, and bulk downloads from SharePoint, OneDrive, and email. Microsoft disclosed it alongside a separate CEO-impersonation fraud campaign that sent over a million emails between August 3 and 5, 2026.
Why it matters
Nothing about passkeys is broken here. The passkey is the pretext. The attacker needs a plausible reason for an employee to visit a sign-in page on a personal phone, and "your passkey needs updating" is currently the most plausible reason available, precisely because so many organizations really are migrating and really are sending employees such notices.
That is the cost of a migration nobody warned users about in advance. A workforce that has been told to expect authentication changes is a workforce primed to comply with one. Any organization rolling out passkeys should be telling people now, in concrete terms, how it will and will not contact them: never by SMS to a personal number, never with a link, always through a channel the user initiates.
The persistence step is the one to hunt for. Registering an attacker-controlled authentication method survives the password reset, the session revocation, and usually the incident closure, which is the same failure we flagged in Issue 7. Alert on every new MFA or passkey registration, treat registrations that follow an anomalous sign-in as an incident by default, and enumerate authentication methods as a standard step in account recovery. The technique is help desk social engineering pointed at the employee rather than the help desk.
Source: The Hacker News
Related on Start with Identity
- BlogA Check Point SmartConsole flaw hands out full admin tokens to unauthenticated attackers
CVE-2026-16232 (CVSS 9.3) lets an unauthenticated remote attacker obtain an application login token for Check Point Security Management and Multi-Domain Managem
- BlogA loose PHP comparison let attackers sign in as WordPress admin through SAML
Two unauthenticated bypasses in the miniOrange SAML 2.0 Single Sign On plugin, CVE-2026-61979 and CVE-2026-15981, treat OpenSSL's error return as a valid signat
- BlogA phishing kit rents an AI voice agent to call theft victims and ask for their 2FA code
SOCRadar documented AnonyMousKIT, a phishing-as-a-service platform built to strip Apple Activation Lock. An AI persona called Alice from Apple Support phones vi
- RecipeAdd passkeys with WebAuthn
Implement passkey registration and authentication with the WebAuthn ceremonies: generate and verify challenges on the server, call navigator.credentials on the
- RankingBest MFA for Enterprises: Top 5 Multi-Factor Authentication Platforms
The best enterprise MFA platforms in 2026: Duo, Microsoft Authenticator, Yubico, RSA SecurID, and HYPR. Ranked for coverage, phishing resistance, and workforce
- RankingBest MFA Solutions: Top 5 Multi-Factor Authentication Tools
The top 5 MFA solutions (Yubico, Duo Security, Microsoft Authenticator, HYPR, Beyond Identity), scored on a 10-dimension rubric, from phishing-resistant hardwar