Microsoft reports that threat actors linked to ShinyHunters, Helix and other extortion gangs are running passkey- and single-sign-on-themed social engineering campaigns against corporate Microsoft accounts, observed since May 2026, in which attackers research target organisations and employees and then call or message them impersonating an internal IT help desk to demand urgent passkey, MFA or SSO updates. Victims are directed to phishing sites resembling Microsoft login pages, with links sometimes sent by SMS to employees' personal phones; Microsoft notes that despite the passkey framing the attackers are not attempting to enrol a passkey, but using the lure to push victims into adversary-in-the-middle phishing that captures credentials and session tokens, or into device-code authentication flows that persuade users to authorise an attacker-controlled client through Microsoft's own legitimate authentication pages. The campaign's distinguishing feature is the pre-attack research investment โ a shift from opportunistic credential harvesting to targeted, identity-focused social engineering that bypasses MFA by capturing the session rather than the password. It is a direct methodological companion to the passkey-phishing wave and the OAuth consent phishing warning already covered this week, and the device-code variant is the harder of the two to detect because it produces genuine authentications rather than anomalous ones.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-12 |
| Source | BleepingComputer |
| Reliability | Tier 2 |