vendor
Social engineering lures pivot from MFA fatigue to passkey pretexts
The passkey-themed phishing wave is a registration drive in disguise, attackers don't want your passkey, they want your session token.
Microsoft Security Research reports active cloud intrusions since May 2026 that open with social engineering calls and SMS messages themed around passkey, MFA, or SSO enrollment. Attackers direct targets to adversary-in-the-middle phishing pages or device-code authentication flows, capturing credentials and session tokens. Once inside, they add their own authentication methods, enumerate SharePoint and OneDrive via Microsoft Graph, and collect mail through REST APIs. The initial compromise often leaves little endpoint telemetry because victims open links on personal mobile devices not onboarded to Defender for Endpoint.