logo

Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts

ID: 3fe7e875-b033-5410-9062-f5221559c182

STIX ID: report--3fe7e875-b033-5410-9062-f5221559c182

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-09-10

Date Updated: 2026-09-11

Author: Mayura Kathir

...
...

Microsoft Security Research observed an ongoing social-engineering campaign (since May 2026) in which attackers impersonate IT helpdesk staff via phone or SMS to lure Microsoft 365 users to fake authentication portals; attackers use AiTM and device-code phishing to obtain OAuth tokens or sessions, register attacker-controlled MFA factors, perform Microsoft Graph reconnaissance, and quietly exfiltrate files and emails from SharePoint, OneDrive, and Exchange Online. The report lists suspected lure domains, behavioral indicators (unusual sign-ins, new auth-method enrollments, Graph API traversal, proxy-associated access), actor attributions, and recommended containment steps such as removing unauthorized auth methods, revoking sessions, and correlating Graph telemetry with data-access events.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.