The phone rings on a Tuesday afternoon. The person on the other end says they are from your IT help desk. They are calm, they know your name, and they say your passkey needs updating right now or you will lose access. So you follow the link they text to your personal phone, and you do exactly what they ask.
That is the shape of an attack Microsoft just disclosed, and it is worth reading closely because it works on careful people, not careless ones.
What Microsoft actually reported
On September 13, 2026, Microsoft disclosed details of two separate campaigns. According to Microsoft, the first was a financial fraud operation that sent over a million scam emails between August 3 and 5, 2026, with attackers masquerading as the chief executive officers of target companies to push accounts payable departments toward Automated Clearing House transfers for a fake ServiceNow subscription.
What makes that first campaign notable is how it was built. Microsoft said the operators used generative AI to create email templates and draft messages tailored to their recipients. This was not one lazy lure. Microsoft’s research team described a campaign that “layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism.” The attackers even plugged real executive names and email addresses into the signatures so the messages looked right to the people reading them.
The second campaign is the one that should get every leader’s attention. Microsoft documented cloud intrusions, detected since May 2026, that start with identity-focused social engineering. According to Microsoft, the attackers call or message a user’s personal phone number, claim to be from the organization’s IT help desk, and urge the person to immediately update their passkey, multi-factor authentication, or single sign-on settings to avoid losing access. The victim gets redirected to a counterfeit site that mimics the real Microsoft sign-in, and is walked through an adversary-in-the-middle or device-code authentication flow that hands over the account.
Microsoft noted the attackers register domains themed around passkeys, SSO enrollment, and identity verification, then append the target company’s name as a subdomain to make the address look legitimate. Once inside, Microsoft said the activity was consistent with “automated collection from compromised cloud identities using proxy-associated infrastructure,” pulling files from SharePoint and OneDrive and collecting mailboxes through APIs.
Microsoft also described how the attackers turned a temporary compromise into a lasting one. According to Microsoft, after getting in, the actor’s first objective was to enroll a multi-factor method under their own control, typically by registering a new phone number, authenticator app, or software-based one-time password token. In one incident Microsoft investigated, a passkey lure was used to launch a device-code phishing attack that took over an account without stealing credentials or cookies, effectively getting around MFA.
Why this one matters to you
Most security advice you have heard for years quietly assumes the danger arrives by email. Enable MFA, do not click strange links, and you are mostly covered. This campaign breaks that assumption on purpose.
The passkey attack starts with a phone call to a personal number, not an email to a work inbox. It uses the language of good security, updating your passkey, enrolling in SSO, to get you to lower your guard. And the payload is not a password. Microsoft’s own reporting shows cases where the attacker never needed the password at all, because the device-code flow let the victim grant access directly.
The AI angle matters too, and not as a headline. The first campaign shows what happens when generative AI removes the friction from writing convincing fraud. The typos and awkward phrasing that used to give scams away are gone. Microsoft said the operators used AI to draft messages tailored to recipients, which means the volume goes up and the quality goes up at the same time. This is exactly the pattern we talk about with clients exploring AI. The same tools that make your team faster make your attackers faster, and the defense is not a single product. It is understanding your people, your systems, and where an attacker would apply pressure.
For a growth-stage company running on Microsoft 365, the exposure is direct. Your identity is your perimeter now. If someone can talk one employee through an authentication flow, they can reach your files, your email, and your finance workflows without tripping a single malware alarm.
What to do this week
You do not need a new tool to close most of this gap. You need a few decisions and one honest conversation with your team.
-
Tell your people the real rule out loud. Your IT team, or your IT provider, will never call to walk them through a passkey or MFA change under time pressure. If a call like that comes in, they hang up and call IT back on a known number. Say it plainly so nobody has to guess in the moment.
-
Turn on your finance out-of-band check. Any request to change payment details or send an ACH transfer gets verified by a second channel, a known phone number, before money moves. The million-email CEO fraud campaign dies against one phone call to the real executive.
-
Review who can add authentication methods and watch for new ones. Microsoft described attackers registering their own phone number or authenticator to keep access. Alerting on new MFA method enrollment is one of the highest-value signals you can turn on.
-
Look at device-code and legacy authentication flows in your tenant. One documented attack used a device-code lure specifically to sidestep MFA. If your organization does not use device-code sign-in for a real reason, restrict it.
-
Check your sign-in logs for anomalous access from unmanaged devices. In at least one case Microsoft investigated, the attacker signed into Microsoft Office Home from an unmanaged device and expanded from there. That is a visible event if someone is looking.
The attackers in this campaign did their homework on your people. The fix is to do the same, to know how your team works so you can tell them exactly what a legitimate request looks like and what a trap looks like.
Common Questions
Are passkeys still safe to use? Yes. The attack does not break passkeys. It tricks people into changing or enrolling authentication methods through a fake process. Passkeys remain a strong defense. The weak point here is the phone call convincing someone to alter their settings.
We already have MFA. Does that protect us? Partly. Microsoft documented cases where the attackers got around MFA using device-code flows or by enrolling their own second factor after gaining access. MFA is necessary and not sufficient. You also need to watch for new authentication methods being added and restrict authentication flows you do not use.
How is AI changing attacks like this? According to Microsoft, the CEO fraud campaign used generative AI to draft tailored emails at scale. That removes the obvious errors that used to expose scams and lets attackers produce convincing, personalized messages in volume. The defense is not a single product. It is knowing your people, systems, and processes well enough to build checks that a convincing message cannot bypass.
What is the single highest-value thing to do first? Tell your team the rule that IT will never call to rush them through a passkey or MFA change, and pair it with an out-of-band verification step for any payment change. Those two habits close most of the exposure this campaign relies on.
Sources
- Microsoft disclosed two campaigns abusing third-party email infrastructure and passkey-themed social engineering: The Hacker News, “Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data” (2026), https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html
- The CEO fraud campaign sent over a million scam emails between August 3 and 5, 2026, and used generative AI to draft tailored messages: The Hacker News, “Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data” (2026), https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html
- The passkey social engineering campaign, detected since May 2026, begins with calls or messages to personal phones impersonating IT help desk and leads to cloud account takeover: The Hacker News, “Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data” (2026), https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html
Since 2002, centrexIT has been the IT and cybersecurity partner for businesses across the western U.S. We help clients adopt AI safely because we already understand their people, systems, data, security posture, and operational risk. Take the 2-Minute Cybersecurity Assessment: https://centrexit.com/assessment/cybersecurity/
The centrexIT team brings decades of combined IT expertise, helping San Diego businesses thrive with secure, reliable technology solutions.
Meet Our Team