Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
ID: 3fe7e875-b033-5410-9062-f5221559c182
STIX ID: report--3fe7e875-b033-5410-9062-f5221559c182
Feed Name: GBHackers
Microsoft Security Research observed an ongoing social-engineering campaign (since May 2026) in which attackers impersonate IT helpdesk staff via phone or SMS to lure Microsoft 365 users to fake authentication portals; attackers use AiTM and device-code phishing to obtain OAuth tokens or sessions, register attacker-controlled MFA factors, perform Microsoft Graph reconnaissance, and quietly exfiltrate files and emails from SharePoint, OneDrive, and Exchange Online. The report lists suspected lure domains, behavioral indicators (unusual sign-ins, new auth-method enrollments, Graph API traversal, proxy-associated access), actor attributions, and recommended containment steps such as removing unauthorized auth methods, revoking sessions, and correlating Graph telemetry with data-access events.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
