Microsoft Warns of Passkey and SSO-Themed Phishing Targeting Microsoft 365 Accounts
What Happened
Microsoft has reported that threat actors linked to ShinyHunters, Helix, and other extortion-focused groups are running social engineering campaigns themed around passkeys and single sign-on (SSO) to compromise corporate Microsoft accounts and steal data from Microsoft 365 services, according to BleepingComputer.
Why It Matters
Passkey and SSO prompts are widely regarded by users as trustworthy, phishing-resistant signals — attackers appear to be exploiting that trust rather than a technical flaw in passkey authentication itself. Groups associated with ShinyHunters have a track record of large-scale data theft and extortion, so successful account compromise here could lead directly to bulk exfiltration of Microsoft 365 data (email, SharePoint, OneDrive) and follow-on extortion demands. Any organization relying on Microsoft 365 for corporate collaboration is a potential target.
What Defenders Should Watch For
- Phishing lures that mimic passkey enrollment/registration or SSO re-authentication prompts, especially unexpected requests to "re-register" a passkey or security key.
- Anomalous authentication events in Entra ID/Azure AD sign-in logs, particularly new passkey/FIDO2 credential registrations from unfamiliar devices or locations shortly after a user reports receiving such a prompt.
- Unusual OAuth consent grants or new MFA/authentication method additions on user accounts.
- Downstream indicators of data staging or exfiltration from Microsoft 365 services (SharePoint, OneDrive, Exchange Online) following suspicious sign-in activity.
- User reports of phishing emails or pages referencing passkeys, security keys, or SSO login issues — treat these as high-priority triage items given the current campaign activity.
- Reinforce user awareness that legitimate passkey/SSO prompts should not be initiated from email links, and validate any credential-registration workflow independently before approving it.
Developing Story
Details on specific indicators of compromise, targeting scope, and technical mechanics of these campaigns are still emerging. This is based on Microsoft's reporting as relayed by BleepingComputer, and this post will be treated as preliminary intel pending further technical details. Read the original report at BleepingComputer.