Passkey-Themed Phishing Is Now Hitting Microsoft 365 Accounts

What happened
Microsoft has warned that threat actors tied to ShinyHunters, Helix, and other extortion crews are running social engineering campaigns built around passkey and single sign-on themes to take over corporate Microsoft accounts and pull data out of Microsoft 365 services. The reporting comes from BleepingComputer, which covered Microsoft's findings.
The hook is the clever part. Passkeys and SSO are things your users have been told are safer, so a message about "enrolling your passkey" or "re-authenticating your single sign-on" reads like good hygiene rather than a threat. Specific indicators, sender domains, and the exact enrollment flows being abused are details worth verifying against Microsoft's own advisory and your tenant's sign-in logs rather than assuming, and if your provider hasn't confirmed those details for your environment, that's the first thing to ask for.

Why this matters for Pittsburgh-area SMBs
Almost every client we work with in the region runs on Microsoft 365. Your email, files, Teams chats, and increasingly your AI tooling all sit behind one identity. That means a single successful account takeover isn't "one compromised mailbox," it's potential access to SharePoint libraries, OneDrive folders, and years of message history. For a 40-person firm, that's the whole business in one place.
The vertical detail matters here. A CPA firm in the middle of extension season has client SSNs, K-1s, and bank detail in mailboxes, and the FTC Safeguards Rule expects you to be able to demonstrate access controls and monitoring around it. A law firm's exposure is privileged client material, with notification and bar-ethics implications on top of breach law. Healthcare practices are looking at a HIPAA breach analysis the moment an account with ePHI in it is confirmed compromised, and "we're not sure what they accessed" is the worst possible answer during that analysis. Defense contractors and their suppliers along the river valleys have a harder problem still: if CUI touches that tenant, a takeover is a CMMC-relevant incident with DFARS 7012 reporting obligations, not just an IT cleanup.
Two more things make extortion-group activity different from commodity phishing. First, these crews steal data and monetize the leverage, so there may be no ransomware, no encryption, no obvious outage, just a quiet export followed by a demand weeks later. Second, they are patient with people. Help desk calls, follow-up messages, and MFA fatigue prompts are all in the playbook, which means your controls have to hold even when a well-meaning employee wants to be helpful.
Manufacturers, don't tune out. Even if your shop floor systems are isolated, your quoting, engineering drawings, and vendor payment instructions live in Microsoft 365. Business email compromise against an AP clerk is still one of the most expensive things that happens to a mid-sized company in Western PA.
What to do about it this week
- Send a plain-language warning to every user today. Tell them that no legitimate IT process will ask them to enroll a passkey or re-authenticate SSO from a link in an unexpected email or chat. Give them one place to report suspicious prompts, and make it clear nobody gets in trouble for reporting a false alarm.
- Audit your Conditional Access policies. Confirm you require compliant or hybrid-joined devices for access to Exchange, SharePoint, and Teams, that legacy authentication is blocked, and that sign-in risk policies are actually enforcing, not just reporting. If you can't say with confidence which policies are in report-only mode, that's your gap.
- Review authentication method registration. Look at who has recently added or changed an MFA or passkey method in your tenant, and set an alert on new registrations. Attacker-added methods are how a one-time compromise becomes durable access.
- Turn on and check your audit trail. Verify mailbox and unified audit logging is enabled tenant-wide and that retention is long enough to answer a regulator's questions months later. Data-loss and information-protection controls in Microsoft 365 are worth configuring now, while nothing is on fire.
- Harden identity verification at the help desk. Write down the steps required before anyone resets a password or MFA method, including a callback to a known number. Social engineering the help desk is cheaper for attackers than breaking cryptography.
- Test one real detection. Ask your team or your provider to show you what alert fires on an impossible-travel sign-in or a mass file download, and who gets paged. Detection without a named responder is documentation, not cybersecurity.
- Map the compliance consequence before it happens. Whether your driver is HIPAA, SOC 2, FTC Safeguards, or CMMC Level 2, decide now who declares an incident, who notifies, and on what clock. Trying to interpret DFARS or breach-notification timelines during hour three of an investigation goes badly.
One bonus item: if you're rolling out AI assistants across your tenant, note that identity compromise now also means access to whatever those tools can reach. A short Copilot readiness review and an acceptable-use policy should be part of the same conversation as identity hardening, not a separate project six months later.
How we help
We manage Microsoft 365 and Azure identity for small and mid-sized organizations across Pittsburgh, which means Conditional Access review, MFA and passkey enrollment monitoring, user awareness training, and 24/7 monitoring through our managed IT and security stack are day-to-day work for us, not a special engagement. Our vCIO team ties that back to your roadmap and your auditors so the controls you pay for are the ones you can actually evidence.
Want a second set of eyes on your tenant's identity configuration? Call us at 724.888.7007 or reach out through the contact form and we'll walk your Microsoft 365 sign-in and Conditional Access settings with you.
Related reading

Fake IT Help Desk Calls Are Targeting Microsoft 365 Executives
Attackers are calling executives while posing as IT help desk to steal Microsoft 365 sessions. Here is what Pittsburgh SMBs should verify and change this week.

Password Spraying Attacks Jump 155x: What M365 Tenants Should Do Now
Password spraying attacks jumped 155x by exploiting MFA gaps in Microsoft 365. Here is what Pittsburgh SMBs should check in their tenant this week.

CISA Flags Critical macOS, SharePoint, vCenter, and Windows IKE Bugs
CISA added actively exploited macOS, SharePoint, vCenter, and Windows IKE flaws to its KEV catalog. Here is what Pittsburgh SMBs should patch and verify this week.