Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Passkey rollouts are now a phishing pretext. Microsoft has tracked campaigns since May 2026 where attackers call staff on personal numbers posing as IT, then push them to a fake Microsoft sign-in page to update a passkey. Once in, they register their own MFA method and spend days pulling mail, SharePoint and OneDrive through the Graph API. Detection has to look at behaviour across Graph calls, not one call at a time.