Cybercriminal groups are using fake passkey update alerts to trick employees into granting access to their Microsoft 365 accounts, according to recent reports. These attackers are then using tools like SharePoint, OneDrive, and Exchange to search for sensitive company data. Microsoft has been monitoring this campaign since May 2026, and it is linked to groups associated with ShinyHunters and Helix. Rather than exploiting software weaknesses, the attackers use social engineering tactics to redirect users to fake login pages or manipulate real Microsoft services to gain session access.
The attackers often pose as IT support and contact employees directly, usually on personal phones, claiming there is an urgent need to update passkeys, multi-factor authentication (MFA), or single sign-on (SSO) to prevent loss of access to work tools. They gather information about employees, their roles, and company structures from public sources and register domains that mimic internal services related to passkey configuration. Their goal is to access an already authenticated session, not to steal passwords directly.
Microsoft has identified two main methods used by attackers. One involves placing a fake login portal between the user and the real Microsoft login page, allowing the attackers to intercept credentials and session tokens after MFA is completed. The second method involves tricking victims into entering a code from a fake support request on a legitimate Microsoft page, which unknowingly validates a hacker-initiated login. Once inside, attackers can access various applications, files, and emails, and use Microsoft Graph to gather information about users, groups, roles, and more.
These attacks are often automated, with operations lasting several hours or days, accessing fewer than 1,000 files or emails per hour to avoid detection. Microsoft has identified specific groups such as Storm-3121, linked to ShinyHunters and Falcon, and Storm-3032, formed by former members of BlackFile now operating under Helix. Other actors in this network use similar techniques.
To protect against these attacks, employees should be cautious of unexpected requests about passkeys, MFA, or SSO, especially if they come through personal phones. A real Microsoft page does not always mean the request is legitimate, as attackers can use official sites to validate unauthorized connections. Verification through official company support channels is strongly advised. Administrators should consider using phishing-resistant MFA methods like FIDO2 passkeys and Windows Hello for Business, and disable device code authentication when not needed. Monitoring for unusual MFA methods and access to Microsoft Graph, SharePoint, OneDrive, or Exchange is also important. If a compromise is suspected, active sessions and tokens should be revoked, passwords reset, and any unauthorized authentication methods removed.
Cybercriminals Exploit Passkey Updates to Infiltrate Microsoft 365 Accounts
AI-rewritten from original reportingHow it works
cybercrimemicrosoft365phishingmfashinyhuntershelix



