How Passkey Phishing Evades Traditional Defenses
Microsoft revealed on September 13, 2026, that threat actors have abused third-party email delivery services to send financial fraud messages and used passkey-themed social engineering to breach cloud environments. The campaigns targeted Microsoft 365 users by leveraging compromised infrastructure to distribute deceptive emails designed to steal credentials and exfiltrate sensitive data.
Latest news
YouTube is tightening rules for low-effort Shorts
Google releases Android 17 QPR 3 Beta 1 for testing
Samsung Galaxy S26 FE Slashes $40 Off Its Launch Price
Meta Launches Muse Gadgets to Bring Brain-Sensing Tech to DIY HardwareThe first campaign involved attackers hijacking legitimate email delivery platforms to blast phishing messages that mimicked financial alerts, tricking recipients into clicking malicious links. These links led to fake login portals where users unknowingly surrendered their passkeys and authentication tokens. Microsoft noted that the use of trusted third-party services allowed the emails to bypass standard spam filters and reach inboxes with high delivery rates.
What Makes These Campaigns Particularly Effective
Unlike credential stuffing or brute force attacks, this method relies on manipulating users into voluntarily handing over authentication details through convincing impersonation. Attackers crafted messages that appeared to come from internal finance teams or payment processors, creating urgency around fake invoices or account verification requests. Once users entered their passkeys on spoofed sites, attackers gained immediate access to cloud resources, including email, SharePoint, and OneDrive, enabling data exfiltration and lateral movement within networks.
The abuse of legitimate email infrastructure significantly increases the credibility of phishing attempts, as messages originate from domains with good reputations. Microsoft emphasized that traditional email security tools often fail to detect such abuse because the sending infrastructure itself is not inherently malicious—only its use is. This allows attackers to maintain low detection profiles while achieving high success rates in credential harvesting.
Frequently Asked Questions
How do attackers use passkey phishing to bypass multi-factor authentication? By tricking users into entering their passkeys on fake login pages, attackers capture the authentication tokens needed to access accounts, effectively bypassing MFA if the token is used immediately before expiration.
Why is third-party email infrastructure abused in these attacks? Compromised or abused legitimate email services allow phishing messages to bypass reputation-based filters, increasing deliverability and making the emails appear trustworthy to recipients and security systems alike.
Comments
Leave a comment