Advisory
Published 2026-09-09
Verified 2026-09-19

Microsoft: passkey-themed helpdesk calls lead to M365 AiTM / device-code compromise

Microsoft Security Blog (9 September 2026) documents active cloud intrusions since May 2026 where callers or SMS messages impersonate internal IT helpdesk on employees’ personal phones, claim a passkey / MFA / SSO config must be updated urgently, and steer victims to adversary-in-the-middle phishing pages or Microsoft device-code authentication flows. Passkey enrollment is usually the lure, not the goal — AiTM captures credentials and session tokens; device-code phishing authorises an attacker-controlled client on legitimate Microsoft pages. Follow-on: actor-enrolled MFA methods, high-volume Microsoft Graph reconnaissance, SharePoint/OneDrive downloads, and Exchange REST collection. Microsoft attributes initial access to Storm-3121 (feeds ShinyHunters / Falcon extortion) and Storm-3032 (Helix / BlackFile splinter) among others. Example lure domains in coverage include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, oktasession[.]com, keysyncos[.]com, oskeysync[.]com (often with company-name subdomains). Defenders: phishing-resistant MFA via Conditional Access; block device-code / auth-transfer where unused; correlate unusual sign-ins with new auth-method registrations and Graph/SharePoint anomalies; revoke sessions and remove rogue MFA methods. Primary: Microsoft Security Blog; wire: BleepingComputer (11 Sep).

Product
Microsoft Entra ID / Microsoft 365 (identity plane)
Versions
n/a (social engineering / AiTM / device-code abuse)
Exploited in Australia?
unknown
Patch to
Enforce phishing-resistant MFA; restrict device-code flows; hunt new MFA enrollments after unusual sign-ins; revoke sessions

Primary: Microsoft Security Blog — passkey-themed social engineering (9 Sep 2026) · Vendor: Microsoft Threat Intelligence · BleepingComputer (11 Sep 2026)

tech identity cloud australia