Complete Story
 

09/27/2026

Passkey phishing attacks: Why Microsoft 365 security can't stop at sign-in

Barracuda

Passkey-themed phishing attacks are being used to compromise Microsoft 365 accounts. Here’s why organizations need identity protection, account takeover detection, and post-sign-in visibility to stop attackers after initial access.

Key takeaways

Passkeys are designed to make phishing attacks harder. So, when attackers started using passkeys as the lure, it got a lot of people’s attention.

Passkey phishing is a social engineering tactic where attackers use passkey, MFA, or single sign-on updates as a lure to trick users into granting access or changing authentication settings.

According to recent research from Microsoft Security Research, threat actors have been impersonating IT help desk staff and contacting employees directly through phone calls and text messages. The message is simple: Your passkey, MFA, or single sign-on settings need updating. Follow these instructions now or risk losing access.

More Info

Printer-Friendly Version