started · updated
Cybersecurity researchers warn of passkey phishing and AI-driven social engineering
Cybersecurity researchers have identified an active social engineering campaign where attackers impersonate IT help desks to facilitate cloud account takeovers. Microsoft Security Research reported observing activity since May 2026, involving attackers using fake passkey setup requests to compromise employee identities.
These attacks often begin with phone calls, SMS, or Microsoft Teams messages directing victims to fraudulent websites that mimic legitimate Microsoft sign-in pages. While the pretext involves updating passkeys or multi-factor authentication (MFA), the primary goal is often to execute adversary-in-the-middle phishing or device-code authentication to capture credentials and session tokens. Once access is gained, attackers have been observed using Microsoft Graph to enumerate and download sensitive files from SharePoint Online and OneDrive.
Broadly, the evolution of social engineering is being driven by advancements in artificial intelligence. AI allows cybercriminals to automate data collection and research targets more efficiently, providing them with the information necessary to create highly convincing and personalized manipulation attempts.