#7
BleepingComputer
general
September 11, 2026 at 17:26 UTC
Passkey-themed phishing attacks lead to Microsoft 365 data theft
By Lawrence Abrams
AI Summary
Microsoft has identified threat actors linked to ShinyHunters, Helix, and other extortion groups using passkey- and SSO-themed social engineering lures to compromise corporate Microsoft 365 accounts and exfiltrate data. The attacks exploit user trust in modern authentication flows — specifically passkey prompts — as phishing vectors, representing an evolution beyond traditional credential-harvesting pages. Security teams should update awareness training to cover passkey-themed phishing as a novel and growing attack vector.
Relevance score: 80.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →