← Back to Feed

Passkey-themed phishing attacks lead to Microsoft 365 data theft

September 11, 2026 · BleepingComputer · Severity: MEDIUM

This article discusses passkey-themed phishing attacks that are targeting Microsoft 365 users to steal their credentials. Attackers send emails about fake passkey setup requests, but the attacks use traditional credential theft methods to compromise accounts.

Key Takeaways

  • Cybercriminals are using passkey-themed phishing emails that trick victims into visiting credential harvesting pages to steal Microsoft 365 account credentials and gain unauthorized access.
  • Despite the modern passkey branding in these attacks, the underlying technique relies on classic credential theft methods rather than exploiting actual passkey technology vulnerabilities.
  • Organizations should educate users to verify any unexpected passkey setup requests through official channels and implement multi-factor authentication to defend against these evolving phishing campaigns.
☕ Buy a Coffee