Passkey-themed social engineering leads to identity and cloud compromise
Executive Summary
Microsoft Security reports that threat actors use passkey-themed social engineering to trick users into revealing MFA credentials, establishing persistence, and then abuse Microsoft Graph for reconnaissance. They target SharePoint, OneDrive, and email data, enabling broader cloud compromise. The post outlines detection signals and mitigation steps.
Intelligence Metadata - Source Publisher: Microsoft Security - Published Date: 2026-09-09T17:41:18+00:00 - Category: threat-intel
Original Description: Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance. The post Passkey-themed social engineering leads to identity and cloud compromise appeared first on Microsoft Security Blog.
"Great talent finds happiness in execution."
— Johann Wolfgang von Goethe