Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

A new phishing tactic has been discovered, where hackers are impersonating Microsoft’s Entra Passkey enrollment process to gain unauthorized access to Microsoft 365 accounts. This cunning approach leverages the trust users have in legitimate company services, making it a particularly effective and insidious form of social engineering.

The attack begins when an unsuspecting user receives an email that appears to be from Microsoft, requesting them to enroll their device with Entra Passkey. The email contains a link or attachment that, if clicked or opened, leads the victim to a fake login page designed to mimic the real thing. Unbeknownst to the user, this page is actually controlled by hackers who use it to harvest the user’s Microsoft 365 credentials. Once obtained, these credentials can be used to access the target’s email, calendar, and other sensitive data.

Entra Passkey, a relatively new security feature from Microsoft, allows organizations to manage passwordless authentication for their employees. It works by using public key cryptography to verify users’ identities without the need for passwords. In this attack, hackers are exploiting the trust that comes with Entra Passkey’s legitimate use, tricking victims into revealing their login credentials.

The affected individuals appear to be Microsoft 365 subscribers who have been targeted through spear phishing emails. These emails are highly tailored and specific to each recipient, making them nearly indistinguishable from genuine communications. This level of personalization is a hallmark of sophisticated social engineering attacks that rely on exploiting human psychology rather than technical vulnerabilities.

This attack highlights the ongoing threat posed by social engineering, even for those who consider themselves tech-savvy. As AI-powered tools continue to evolve and improve, so too do the tactics used by hackers to bypass security measures. It’s a constant cat-and-mouse game where both sides are continually adapting their strategies.

To protect yourself against similar attacks, it’s essential to remain vigilant when receiving unsolicited emails or requests for login credentials. Always verify the authenticity of such communications through alternative channels and never click on suspicious links or open attachments from unknown sources.


Source: The Hacker News — 2026-07-10