Passkey-themed phishing attacks lead to Microsoft 365 data theft
Summary
Microsoft has reported that threat actors, including groups like ShinyHunters and Helix, are employing social engineering tactics focused on passkey and single sign-on (SSO) themes. These attacks aim to compromise corporate Microsoft 365 accounts, leading to data theft from these services.
IFF Assessment
The article describes active threat actor campaigns successfully compromising corporate accounts and stealing data, representing a direct threat to defenders.
Defender Context
Defenders should be aware of evolving social engineering tactics that leverage emerging authentication methods like passkeys and SSO. Training users to scrutinize requests related to these features and implementing robust multi-factor authentication (MFA) solutions are crucial to mitigate these risks.