Skip to content
Bellator Cyber Guard
News7 min readStandard

Microsoft Warns of Passkey Phishing Hitting Cloud Accounts

Microsoft disclosed passkey-phishing attacks and a mass CEO-spoofed scam email campaign hitting Microsoft 365 users in September 2026.

By Bellator Cyber Guard Security Team

Microsoft Discloses Two Active Campaigns Against Cloud Accounts

Microsoft disclosed on September 13, 2026, that it identified two separate attack campaigns targeting its customers: one using passkey-themed social engineering to break into Microsoft cloud accounts and steal data, and a second flooding inboxes with financial fraud emails that impersonate chief executive officers. Both campaigns matter for the same reason: they show attackers adapting their lures to whatever authentication method or business process a target organization trusts most, whether that is a passwordless login or a wire transfer request from the boss.

According to Microsoft, the CEO-impersonation campaign sent more than one million scam emails between August 3 and August 5, 2026, using third-party email delivery infrastructure rather than compromised Microsoft systems. Microsoft says the second campaign used passkey-related social engineering to trick victims into actions that let attackers into their cloud accounts and out with sensitive data. Microsoft's disclosure did not specify the exact technical mechanism used to defeat or bypass passkey protections in that campaign, so readers should treat the passkey-phishing details as a developing story rather than a fully documented technique.

Key Takeaway

A passkey is a FIDO2-based passwordless credential tied to a physical device or platform authenticator, designed to resist the credential-theft techniques that make traditional password phishing work. Microsoft's disclosure shows that even passkey-protected accounts are not immune to social engineering: attackers do not need to crack the cryptography if they can talk a user into approving a fraudulent registration, session, or recovery step. Organizations that treat passkey rollout as a finish line rather than one control among several are at higher risk.

Why Passkey Phishing Is Different From Password Phishing

Passkeys, standardized under the FIDO Alliance's FIDO2 and WebAuthn specifications, eliminate the shared secret that classic phishing kits harvest: there is no password to type into a fake login page. That has pushed attackers toward a different target: the human decision points around enrollment, account recovery, and device trust rather than the credential itself. Common patterns documented across the industry include fake "security upgrade" prompts urging users to register a new passkey on an attacker-controlled device, fraudulent help-desk calls requesting a recovery code, and lookalike sign-in pages that push a victim toward a legacy fallback authentication method that is easier to intercept. Microsoft's advisory does not confirm which of these techniques, if any, was used in the campaign it disclosed, so treat this as general context on the attack category rather than a description of this specific incident.

Third-Party Email Infrastructure Complicates Detection

Microsoft says the CEO-fraud campaign relied on third-party email delivery infrastructure rather than sending directly from attacker-owned domains. Using established bulk-email or marketing platforms to route scam messages can help attackers pass basic sender-reputation and authentication checks, since the underlying infrastructure often has a legitimate track record. This does not mean the platforms themselves were complicit or compromised; Microsoft's description points to abuse of legitimate delivery services rather than a claim of wrongdoing by any named vendor. For defenders, it means that SPF, DKIM, and DMARC checks alone are not sufficient signals when the sending infrastructure is genuinely authorized, and content-based and behavioral detection matter more.

What Healthcare Practices, Tax Firms, and Small Businesses Should Do Now

Both campaigns target the same weak point: a person making a fast decision under perceived authority or urgency. Practical steps this week:

Verify wire and payment requests out of band. Any email that appears to come from a CEO or executive requesting a payment, gift card purchase, or vendor change should be confirmed by phone or in person using a known contact number, not one supplied in the email.

Lock down passkey and MFA enrollment. Restrict who can register a new passkey or authenticator to a device, require admin approval or a second verified channel for enrollment changes, and disable legacy authentication fallbacks (SMS codes, security questions) where your identity provider allows it, since these are the paths attackers push victims toward when a phishing-resistant method is in place.

Train staff on passkey-specific lures, not just password phishing. Most security awareness content still focuses on fake login pages asking for passwords. Add examples of fraudulent "re-register your passkey" prompts and impersonated IT help-desk calls to your training.

Audit third-party senders in your email flow. If your organization uses marketing or transactional email vendors, confirm your DMARC policy is set to quarantine or reject and review which third parties are authorized to send on your behalf.

Monitor for anomalous cloud sign-ins. Enable and review sign-in risk alerts in Microsoft Entra ID (formerly Azure AD) or your identity provider for new device registrations, impossible-travel sign-ins, and new authenticator enrollments, particularly for accounts with access to financial systems or patient and client records.

For organizations subject to HIPAA, a compromised cloud account used to exfiltrate data can trigger breach-notification obligations depending on what data was accessed, so incident response plans should already map out how to determine scope quickly if a cloud account is compromised. Consult your compliance officer or counsel before making a breach determination, since that assessment depends on facts specific to each incident.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

See whether the service fits

Choose a security approach that fits the way you already work

Start with the outcome and scope. A good fit is clear about who it is for, what is covered, how implementation works, and what happens when the service detects a problem.

People also look for

Keep exploring Network & cloud security

Protect the connections, cloud accounts, and remote-work paths that people rely on every day.