Select a theme from the list.
Insights

From our experts

Latest
Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformSlim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development Platform
Security Insight

Passkey Reset Scams Turn Strong Authentication Into Cloud Persistence

Passkey Reset Scams Turn Strong Authentication Into Cloud Persistence
Photo by Yan Krukau on Pexels

Microsoft has identified an active social-engineering campaign in which attackers impersonate IT support and direct employees to fraudulent passkey, MFA or single sign-on enrollment pages. After compromising an identity, the intruders add their own authentication methods, investigate cloud resources and collect information from email, SharePoint and OneDrive.

Passkeys are designed to remove many of the weaknesses associated with passwords, but Microsoft has documented a campaign showing that strong authentication cannot compensate for a manipulated user or an inadequately protected enrollment process. The attackers are not breaking passkey cryptography. Instead, they are persuading employees to help register authentication methods controlled by the intruder.

A convincing identity attack

The campaign frequently begins with a call or message sent to an employee's personal phone. Someone claiming to represent the corporate helpdesk warns that a passkey, multifactor authentication or single sign-on configuration must be updated to prevent an interruption. The victim is then directed to an impersonation site resembling a legitimate Microsoft sign-in page.

Once access is obtained, the attackers establish persistence by adding authentication methods to the compromised account. Microsoft observed unusual sign-ins followed by Microsoft Graph reconnaissance, large SharePoint and OneDrive downloads, and email collection through application programming interfaces. This allows the operation to move from a single identity compromise to automated discovery and potential data exfiltration across cloud services.

Why passkeys are not the problem

It would be a mistake to interpret this activity as evidence that passkeys have failed. The underlying security issue is control of the enrollment, reset and recovery workflow. If an attacker can convince a user or helpdesk employee to authorize a new authenticator, the organization may treat the attacker's device as legitimate.

In my view, companies must protect authentication changes with the same rigor applied to privileged administrative actions. A successful login should not automatically make every subsequent identity-management event trustworthy.

Defensive priorities

  • Require strong identity verification before helpdesk-assisted MFA or passkey resets.
  • Notify users and security teams whenever a new authentication method is registered.
  • Restrict application consent and require administrative approval for sensitive Microsoft Graph permissions.
  • Monitor for unusual authentication enrollment, rapid cloud enumeration and high-volume file or mailbox access.
  • Revoke active sessions and remove unauthorized authentication methods during incident response.

I believe the durable lesson is that identity security must cover the entire credential lifecycle. Passkeys can prevent password theft, but enrollment and recovery remain powerful control points that attackers will continue to target.

Talk to our team →

Latest

Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesSep 10, 2026Unpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemSep 10, 2026Passkey Reset Scams Turn Strong Authentication Into Cloud PersistenceSep 10, 2026Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path