Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.
The activity has been observed since May 2026 and begins with the attackers researching targeted organizations and employees before calling or messaging victims while impersonating corporate IT help desks.
The attackers tell employees that they must urgently update a passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to avoid losing access to corporate systems.
Victims are then directed to phishing sites designed to resemble legitimate Microsoft login pages, with links sometimes sent through SMS messages to employees' personal phones.
Microsoft says that while the lures frequently revolve around passkeys, the attackers are not attempting to enroll a passkey.










