This alert may not be shared outside your organization, Do Not Repost or send, place on other websites, List servers, or send to others via email, including other associations or parties. Members and Law enforcement use only. Contact us for any permissions. To do otherwise will result in the loss of membership.
Complete Story
09/27/2026
Passkey phishing attacks: Why Microsoft 365 security can't stop at sign-in
Barracuda
Passkey-themed phishing attacks are being used to compromise Microsoft 365 accounts. Here’s why organizations need identity protection, account takeover detection, and post-sign-in visibility to stop attackers after initial access.
Key takeaways
- Passkeys remain strong, but attackers are using passkey-related messages as social engineering lures.
- The real risk begins after attackers gain access to a trusted Microsoft 365 account.
- Security teams need visibility across identity, email, cloud apps, and data activity.
- Account takeover detection and post-delivery remediation are critical when prevention fails.
Passkeys are designed to make phishing attacks harder. So, when attackers started using passkeys as the lure, it got a lot of people’s attention.
Passkey phishing is a social engineering tactic where attackers use passkey, MFA, or single sign-on updates as a lure to trick users into granting access or changing authentication settings.
According to recent research from Microsoft Security Research, threat actors have been impersonating IT help desk staff and contacting employees directly through phone calls and text messages. The message is simple: Your passkey, MFA, or single sign-on settings need updating. Follow these instructions now or risk losing access.
More InfoAlerts
The FRPA alert system distinguishes us from other groups by gathering and providing information to law enforcement, retailers AND financial institutions.
more informationResources
Your electronic library to help in fighting financial fraud for all of our partners.
more information
