Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Hackers have discovered a new tactic to gain unauthorized access to sensitive Microsoft cloud accounts, exploiting user trust in their passkeys. The attackers use phishing emails that mimic legitimate login prompts, tricking victims into revealing their passkeys and subsequently taking control of their cloud resources.

Microsoft’s cloud services, which include Azure Active Directory (AAD) and Office 365, are particularly vulnerable to this type of attack. These services rely on a concept called “passkey authentication,” where users provide a single piece of information – the passkey – to access multiple connected applications. When an attacker obtains a user’s passkey through phishing, they can seamlessly log in to associated cloud resources without needing additional credentials.

The attackers use this stolen passkey to move laterally within a company’s network, exfiltrating sensitive data and potentially disrupting business operations. According to recent reports, several organizations have already fallen victim to these attacks, with hackers making off with confidential information and intellectual property. Microsoft has acknowledged the vulnerability but so far, it has not provided a clear timeline for patching or mitigating this issue.

The phishing emails used in these attacks are designed to look like legitimate login prompts from Microsoft. They often contain the company’s logo and may even appear to be coming directly from AAD. These messages typically request that users provide their passkey “for verification purposes” or “to update account information.” When a user responds with their passkey, the attackers capture this sensitive data and use it to gain access to connected cloud resources.

The implications of these attacks are significant, particularly for organizations that have invested heavily in Microsoft’s cloud services. A single compromised passkey can grant hackers unfettered access to an entire company’s digital assets, allowing them to move undetected through the network. To protect against this type of attack, users should be cautious when receiving login prompts via email and never provide sensitive information without verifying the requestor’s identity.

In light of these attacks, it is essential for organizations to reassess their cloud security posture and take steps to harden their passkey authentication processes. This can involve implementing additional verification measures, such as two-factor authentication or biometric checks, to ensure that only authorized users have access to connected resources. Users should also remain vigilant when receiving emails requesting sensitive information and report any suspicious activity to their IT teams immediately.


Source: The Hacker News — 2026-09-13