Select a theme from the list.
Insights

From our experts

Latest
Gigabud Hides Banking Fraud Inside Android Work ProfilesSurfshark Test Server Breach Exposes the Security Gap Between Development and ProductionAI-Polished CEO Fraud Targets Finance Teams With Million-Email BlitzSlim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingGigabud Hides Banking Fraud Inside Android Work ProfilesSurfshark Test Server Breach Exposes the Security Gap Between Development and ProductionAI-Polished CEO Fraud Targets Finance Teams With Million-Email BlitzSlim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session Hijacking
Security Insight

Passkey Reset Scams Turn Strong Authentication Into Cloud Persistence

Passkey Reset Scams Turn Strong Authentication Into Cloud Persistence
Photo by Yan Krukau on Pexels

Microsoft has identified an active social-engineering campaign in which attackers impersonate IT support and direct employees to fraudulent passkey, MFA or single sign-on enrollment pages. After compromising an identity, the intruders add their own authentication methods, investigate cloud resources and collect information from email, SharePoint and OneDrive.

Passkeys are designed to remove many of the weaknesses associated with passwords, but Microsoft has documented a campaign showing that strong authentication cannot compensate for a manipulated user or an inadequately protected enrollment process. The attackers are not breaking passkey cryptography. Instead, they are persuading employees to help register authentication methods controlled by the intruder.

A convincing identity attack

The campaign frequently begins with a call or message sent to an employee's personal phone. Someone claiming to represent the corporate helpdesk warns that a passkey, multifactor authentication or single sign-on configuration must be updated to prevent an interruption. The victim is then directed to an impersonation site resembling a legitimate Microsoft sign-in page.

Once access is obtained, the attackers establish persistence by adding authentication methods to the compromised account. Microsoft observed unusual sign-ins followed by Microsoft Graph reconnaissance, large SharePoint and OneDrive downloads, and email collection through application programming interfaces. This allows the operation to move from a single identity compromise to automated discovery and potential data exfiltration across cloud services.

Why passkeys are not the problem

It would be a mistake to interpret this activity as evidence that passkeys have failed. The underlying security issue is control of the enrollment, reset and recovery workflow. If an attacker can convince a user or helpdesk employee to authorize a new authenticator, the organization may treat the attacker's device as legitimate.

In my view, companies must protect authentication changes with the same rigor applied to privileged administrative actions. A successful login should not automatically make every subsequent identity-management event trustworthy.

Defensive priorities

  • Require strong identity verification before helpdesk-assisted MFA or passkey resets.
  • Notify users and security teams whenever a new authentication method is registered.
  • Restrict application consent and require administrative approval for sensitive Microsoft Graph permissions.
  • Monitor for unusual authentication enrollment, rapid cloud enumeration and high-volume file or mailbox access.
  • Revoke active sessions and remove unauthorized authentication methods during incident response.

I believe the durable lesson is that identity security must cover the entire credential lifecycle. Passkeys can prevent password theft, but enrollment and recovery remain powerful control points that attackers will continue to target.

Talk to our team →

Latest

Gigabud Hides Banking Fraud Inside Android Work ProfilesSep 11, 2026Surfshark Test Server Breach Exposes the Security Gap Between Development and ProductionSep 11, 2026AI-Polished CEO Fraud Targets Finance Teams With Million-Email BlitzSep 11, 2026Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesSep 10, 2026Unpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemSep 10, 2026Passkey Reset Scams Turn Strong Authentication Into Cloud PersistenceSep 10, 2026

Most read

1Microsoft Redraws the Security Boundary for Edge AI2Ted Implant Turns Compromised HAProxy Servers Into Invisible Interception Points3French Hospital Fine Turns Weak Identity Controls Into a GDPR Warning4IDScan Lawsuits Put Mass Identity Collection Under the Microscope5Microsoft Prepares Windows Customers for a Faster Era of AI-Driven Patching6Scattered Spider's Cyberattack on Marks & Spencer Exposes Retail Vulnerabilities