Fake passkey setup requests lead to Microsoft 365 compromises
Microsoft Security Research linked cloud account compromises to attacks in which criminals call employees posing as IT support and ask them to update a passkey or sign-in settings. Attacks tracked since May: hackers added their own authentication methods, explored resources via Microsoft Graph and downloaded files from SharePoint and OneDrive, sometimes accessing Exchange Online mail.
- Attacks tracked since May, several accounts affected
- Attackers added their own authentication methods and obtained session tokens
- Users, permissions and files explored via Microsoft Graph
- SharePoint and OneDrive files downloaded, Exchange mail sometimes read
Read next
Security