Passkey-themed lures can lead from identity theft to cloud data access

BRIEF
Microsoft reports a passkey-themed social-engineering campaign that can turn an identity compromise into broader Microsoft cloud access. In the described attack chain, threat actors use familiar passkey or authentication messaging to persuade users to disclose identity information or complete an attacker-controlled authentication flow. Once access is obtained, attackers may establish persistence around multifactor authentication, conduct reconnaissance through Microsoft Graph, and reach data in SharePoint, OneDrive, and email. The passkey theme can make a malicious request appear to be a legitimate security improvement, but the technology itself is not the issue; the risk depends on the message, destination, authentication process, and resulting account changes. Defenders should therefore connect identity and cloud investigations rather than treating an initial phishing report as an isolated event. Useful review areas include newly added authentication methods, suspicious sessions or tokens, application and consent activity, unusual Graph use, and access to collaboration data. The supplied material does not quantify victims, campaign duration, or overall impact. Organizations should focus on detecting unauthorized persistence and correlating authentication, application, email, and file-access activity when investigating suspected compromise.
WHY IT MATTERS
Identity compromise can become a cloud compromise even when an organization uses multifactor authentication. If an attacker persuades a user to complete a malicious authentication step or adds persistence, later access may look more like a valid session than a conventional password attack. Graph-based reconnaissance and access to collaboration stores can expose email, documents, and organizational relationships. The reported chain reinforces the need to monitor authentication changes, consent and application activity, unusual Graph use, and data access in combination. Its presence does not show that every passkey-related message is malicious, so controls should evaluate context and destination rather than block the technology itself.