Passkey-themed phishing attacks lead to Microsoft 365 data theft
BLUF
Extortion gangs are weaponizing passkey adoption to bypass security and exfiltrate corporate data.
NEWS
Microsoft identified campaigns by groups like ShinyHunters using social engineering to mimic passkey prompts. These attacks successfully compromise corporate accounts, leading to unauthorized access and data theft from Microsoft 365 environments. The activity specifically targets users transitioning to passwordless workflows.
Why I Care
This compromises the security benefits of passwordless authentication and exposes organizations to significant data breaches and ransomware extortion. Any business using Microsoft 365 with passkeys enabled is at immediate risk.
Next Steps
Security teams must audit recent sign-in logs for anomalies and conduct urgent user awareness training on verifying authentic passkey prompts. Administrators should enforce strict conditional access policies to block suspicious authentication attempts immediately.
Source: BleepingComputer ·