Passkey-themed phishing attacks lead to Microsoft 365 data theft
Threat actors exploit passkey and single sign-on social engineering to compromise corporate accounts

Key Takeaways
- Passkey-themed phishing campaigns are being used to target corporate Microsoft 365 accounts.
- Threat actors linked to ShinyHunters, Helix, and other extortion gangs are involved.
- Attacks rely on social engineering mimicking passkey and single sign-on prompts.
- Successful compromises result in data theft and account takeover.
- User awareness and verification of passkey/SSO prompts are recommended mitigations.
Quick answers
- What happened?
- Microsoft has warned that threat actors linked to extortion gangs such as ShinyHunters and Helix are conducting passkey-themed phishing campaigns targeting corporate Microsoft 365 accounts. The attacks use social engineering to trick users into revealing passkey credentials or approving single sign-on prompts, resulting in data theft and account compromise. The campaign was reported on September 11, 2026, and affects corporate Microsoft accounts globally.
- Which products are affected?
- Microsoft 365
- What should defenders do?
- Users and organizations should verify all passkey enrollment and single sign-on prompts through official channels, implement user awareness training focused on passkey-themed phishing, and enforce multi-factor authentication beyond passkey credentials where possible.
Microsoft has alerted that threat actors associated with extortion groups including ShinyHunters and Helix are launching passkey-themed phishing attacks to compromise corporate Microsoft 365 accounts. The social engineering campaigns mimic passkey enrollment and single sign-on prompts to deceive users into credential disclosure or approval of unauthorized access requests. Successful attacks have led to data theft from Microsoft 365 services and corporate account compromise. The incidents were reported on September 11, 2026, and target corporate accounts globally. Microsoft 365 security teams are likely issuing guidance on recognizing such phishing attempts, though no technical exploit details beyond the social engineering component have been disclosed. The threat actor affiliations and exact scope of the campaign remain under investigation and should be verified through additional sources.
Security Details
Threat actors are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. No technical exploit beyond social engineering has been disclosed.
Affected products
Microsoft 365
Mitigation
Users and organizations should verify all passkey enrollment and single sign-on prompts through official channels, implement user awareness training focused on passkey-themed phishing, and enforce multi-factor authentication beyond passkey credentials where possible.
Sources
BleepingComputer
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Sep 11, 2026 · 17:26
Original link
Related Security News

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.




