Microsoft 365 Accounts Are Being Hijacked Through Fake Passkey Alerts


Forg365 microsoft 365
Image credit: Microsoft

Extortion gangs are using passkey, MFA, and SSO-themed phishing attacks to compromise corporate Microsoft accounts and steal large amounts of cloud data.

Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion groups have adopted the technique, according to BleepingComputer.

The attacks often begin with criminals impersonating an organization’s IT help desk through phone calls or messages. They tell employees that they must urgently update their passkey, MFA configuration, or SSO settings to prevent losing access to corporate systems.

Attackers use AiTM and device-code phishing

Victims receive links to phishing pages that closely resemble legitimate Microsoft authentication pages.

Attackers then rely on adversary-in-the-middle phishing, also known as AiTM, or device-code authentication to take control of the account.

AiTM pages can capture both login credentials and authenticated session tokens. Stolen session tokens can allow attackers to access an already authenticated account without repeating the normal login process.

Device-code phishing uses a different approach. Attackers provide victims with a device code and convince them to enter it on Microsoft’s legitimate authentication page.

Once the victim approves the request, Microsoft issues an authentication token to an attacker-controlled OAuth application.

This can give the attacker account access without requiring another MFA challenge.

The compromise can also spread beyond Microsoft 365 through connected SSO services. Depending on the organization’s configuration, attackers could potentially reach services such as Salesforce, Google Workspace, Dropbox, Adobe, SAP, Slack, Zendesk, and Atlassian.

Attackers add their own MFA methods

After compromising an account, attackers often register additional authentication methods that they control.

These can include new phone numbers, authenticator applications, and software-based one-time-password tokens.

Adding their own MFA methods helps attackers maintain access even after the initial phishing session ends. They can then complete future authentication challenges without needing the victim’s involvement.

Organizations should pay particular attention to unusual sign-ins immediately followed by new MFA registrations.

Microsoft 365 data theft can continue for days

Attackers also use Microsoft Graph to map the victim organization’s cloud environment and identify valuable accounts and data.

Microsoft observed large-scale data collection from SharePoint Online and OneDrive for Business, while some incidents also involved Exchange Online email accessed through REST APIs.

Security logs may show large numbers of FileAccessed and FileDownloaded events during these attacks.

Microsoft also observed the python-httpx user agent, suggesting that attackers automate at least part of the collection process.

However, the groups do not always download data as quickly as possible.

Instead, they may spread collection activity across several hours or multiple days, often keeping activity below 1,000 files or emails per hour. This slower approach can make malicious activity look more like normal user behavior.

Microsoft recommends phishing-resistant MFA

Microsoft recommends monitoring for suspicious sign-ins followed by MFA registration changes, as well as unusual Microsoft Graph activity that leads to SharePoint, OneDrive, or Exchange access.

If attackers compromise an account, administrators should revoke active sessions and authentication tokens immediately, reset the user’s credentials, and remove any malicious authentication methods or mailbox rules.

Affected users should also re-register their authentication methods.

Microsoft recommends deploying phishing-resistant MFA and restricting sensitive cloud resources to managed devices where possible.

Organizations that do not need device-code authentication should also consider disabling it to reduce the attack surface.

In other security news, Anthropic has blocked attempts to abuse Claude, while Google advises users to update their systems to protect against the BlueMoon Exploit Kit.

More about the topics: Microsoft 365, security

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages