Attackers use passkey-themed scams to hijack Microsoft 365 accounts

Summary

Attackers are using social engineering tactics themed around passkeys to trick employees into compromising their Microsoft 365 accounts. These attacks often begin with impersonation of IT helpdesk staff, leading victims to phishing pages or device-code authentication flows to gain unauthorized access. The ultimate goal is to compromise cloud identities, enabling attackers to register their own authentication methods and access sensitive data.

IFF Assessment

FOE

This article details a new social engineering technique used by attackers to bypass authentication mechanisms and gain access to cloud accounts, representing a significant threat to defenders.

Defender Context

Defenders need to be aware of these passkey-themed social engineering attacks targeting Microsoft 365 accounts. It's crucial to educate employees about the risks of unsolicited IT requests and the potential for adversary-in-the-middle (AiTM) and device-code authentication bypasses. Strengthening authentication policies and user awareness training is paramount to prevent these types of identity compromises.

Read Full Story →