PGH Networks

Passkey Phishing Is Now Targeting Microsoft 365 Tenants

September 13, 2026· PGH Networks Team· 5 min readCloud & Microsoft 365
Passkey Phishing Is Now Targeting Microsoft 365 Tenants

What happened

Microsoft has published details on two active campaigns aimed at cloud accounts, as reported via feeds.feedburner.com in Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data. In the first campaign, attackers leaned on third-party email delivery infrastructure to push more than a million financial-fraud scam messages between August 3 and August 5, 2026, impersonating chief executives to pressure recipients into moving money.

The second thread is the one that should get your attention: passkey-themed social engineering used to gain access to cloud environments, followed by data exfiltration. In other words, the same "please finish setting up your secure sign-in" prompt your staff has been trained to expect is now the bait. The public reporting is high level, so treat specific indicators, affected sending platforms, and exact lure wording as details to verify against Microsoft's own advisory rather than assumptions to act on blindly.

Two small electronic devices on a wooden surface

Why this matters for Pittsburgh small and mid-sized businesses

Two things make this campaign pattern especially unkind to a 10-to-200-person company in Western PA.

First, passkeys are new enough here that nobody is suspicious of them. Many firms in the region rolled out or are still rolling out phishing-resistant sign-in this year. A message telling a paralegal or staff accountant to "register your passkey before your password expires" lands in a gap where the user has no mental model for what a legitimate enrollment looks like. Attackers do not need to defeat the cryptography behind passkeys, they only need to convince someone to enroll a credential the attacker controls, or to abandon the strong method for a weaker fallback.

Second, the CEO-impersonation wave is a direct hit on the workflows that define your vertical. CPA firms are fielding client wire instructions. Law firms are moving retainer and settlement funds through trust accounts, where an errant transfer creates an IOLTA and bar-reporting problem on top of the loss. Manufacturers are approving vendor banking changes with a two-person AP department. Medical practices are handling billing correspondence that sits next to PHI. Financial services firms are living under the FTC Safeguards Rule, which expects documented access controls and incident response, not good intentions.

For defense contractors, the exfiltration half is the expensive half. If controlled unclassified information leaves a mailbox or SharePoint site, you are into DFARS 7012 reporting territory and a CMMC assessment conversation that just got much harder. Same logic for HIPAA covered entities: a hijacked mailbox is a presumed breach until your forensics say otherwise, and "we had MFA" is not a defense if the attacker enrolled their own factor.

The uncomfortable part is that these attacks are cheap to run at scale, and a 40-person firm's tenant is configured almost identically to a 4,000-person one. Attackers are not choosing you for your size. They are choosing you because your Conditional Access policies were probably set up once and never revisited.

What to do about it this week

  1. Lock down authentication-method registration. In Entra ID, require a compliant or hybrid-joined device, or a trusted network, for the "Register security information" action. This single Conditional Access policy is the difference between an attacker adding their own passkey from an unknown device and getting stopped cold.
  2. Audit every authentication method on every account. Pull the report of registered methods and look for factors added in the last 90 days, roughly since mid-June. Anything you cannot tie to a known onboarding or device refresh gets removed and re-enrolled in person. Prioritize executives, finance, HR, and anyone with mailbox delegation.
  3. Kill the weak fallbacks. If SMS and voice call are still enabled as authentication methods, disable them. If legacy authentication protocols are still permitted anywhere in the tenant, block them. Verify with sign-in logs rather than trusting the policy list.
  4. Tell people exactly what real passkey enrollment looks like. One short internal note: we will only ask you to enroll from your company device, we will never link to enrollment from an email, and here is who to call to confirm. Naming the specific lure removes its power. If you have an acceptable-use policy refresh scheduled, fold this in.
  5. Put a hard out-of-band rule on money movement. Any new or changed payment instruction requires a callback to a phone number already on file, never a number in the email thread. Write it down, have leadership sign it, and make it explicit that emails appearing to come from the CEO are not an exception, they are the pattern being abused.
  6. Turn on the detections that catch the second stage. Impossible-travel and anomalous-download alerts, mailbox forwarding-rule alerts, and external sharing alerts are how you find exfiltration in hours instead of months. Confirm someone is actually receiving and reviewing those alerts, and that your Microsoft 365 licensing tier supports the audit retention your regulator expects.
  7. Rehearse the first hour. Who revokes sessions, who resets methods, who notifies counsel or your contracting officer. A tabletop over lunch is enough to expose the gaps, and it becomes evidence for your SOC 2 or CMMC file.

Items 1 through 3 are configuration work you can finish this week. Items 4 and 5 are policy and cost nothing. Items 6 and 7 belong on your technology roadmap if they are not already there.

How we help

We manage Microsoft tenants for firms across Pittsburgh every day, which means Conditional Access design, authentication-method hygiene, EDR and MDR coverage, and the audit evidence your assessor or insurer will ask for are already part of our managed IT work, not a special project. If you are not certain who owns registration policy in your tenant, that is the question worth answering before the next wave of these emails arrives.

Call us at 724.888.7007 or reach out through the contact form and we will walk your tenant configuration with you.

Share

Related reading

Call usBook a meeting