Security / WORLD

Microsoft warns of passkey-themed identity phishing campaign

Microsoft said social engineering that impersonates passkey registration and single sign-on can compromise employee identities and cloud accounts.

Reading sizeSources ↓Share story ↗

Microsoft Threat Intelligence described on 9 September 2026 a global social-engineering campaign that impersonated passkey enrollment and single sign-on. The company said multiple threat actors used email and voice communications to direct employees toward identity compromise and access to Microsoft 365 cloud services.

Microsoft advised organisations to correlate unusual sign-ins with new authentication-method registrations, Microsoft Graph reconnaissance and high-volume file downloads. Its assessment attributes activity to several threat clusters; it does not say that every campaign step occurred in every incident.

Data

Timeline

Security development

Security event or institutional action reported by the source.

  1. · Occurred

    Microsoft disclosed a passkey-themed social engineering campaign

    The company said attackers used passkey- and single-sign-on-themed messages to target employees and pursue account access and cloud data.

Methodology

The event date and description summarise the action reported by the source; no additional measurement or forecast is made.

Updated:

Structured coverage

Subjects and places

Subject proposals

Taxonomy version: IPTC Media Topics 2026-Q2

Continue reading

Security

Google reports new ways threat actors are using artificial intelligence

Google Threat Intelligence Group said attackers are targeting AI workflows and cloud resources, including a second-quarter 2026 campaign that moved from cloud access to mass credential harvesting in under six hours.

Google Threat Intelligence Group1 min read
Data included