Microsoft warns of passkey-themed identity phishing campaign
Microsoft said social engineering that impersonates passkey registration and single sign-on can compromise employee identities and cloud accounts.
Event / data period: 2026-05
Published: · Updated:
Microsoft Threat Intelligence described on 9 September 2026 a global social-engineering campaign that impersonated passkey enrollment and single sign-on. The company said multiple threat actors used email and voice communications to direct employees toward identity compromise and access to Microsoft 365 cloud services.
Microsoft advised organisations to correlate unusual sign-ins with new authentication-method registrations, Microsoft Graph reconnaissance and high-volume file downloads. Its assessment attributes activity to several threat clusters; it does not say that every campaign step occurred in every incident.
Data
Security development
Security event or institutional action reported by the source.
- · Occurred
Microsoft disclosed a passkey-themed social engineering campaign
The company said attackers used passkey- and single-sign-on-themed messages to target employees and pursue account access and cloud data.
Methodology
The event date and description summarise the action reported by the source; no additional measurement or forecast is made.
Updated:
Subjects and places
Subject proposals
- Cyber crimeSuggested
- Subject suggested from the title or summary: phishingwww.microsoft.com ↗