Cybercriminals Deploy Fake Passkey Updates To Hijack Microsoft Cloud Accounts

TechnologyCybersecuritySeptember 14, 2026· Source: @TheHackersNews

By 813 Staff

Cybercriminals Deploy Fake Passkey Updates To Hijack Microsoft Cloud Accounts

Engineers and executives are reacting to Cybercriminals Deploy Fake Passkey Updates To Hijack Microsoft Cloud Accounts, according to The Hacker News (@TheHackersNews) (in the last 24 hours).

Source: https://x.com/TheHackersNews/status/2099079014849880541

The cybersecurity industry spent the past two years telling enterprises that passkeys would end phishing as we know it. That narrative is now colliding with reality. According to a report surfaced this week by The Hacker News (@TheHackersNews), attackers are deploying counterfeit passkey update prompts designed to hijack Microsoft cloud accounts, turning the very authentication upgrade meant to defeat credential theft into a delivery mechanism for account takeover.

The campaign, first flagged on September 13, targets Microsoft's cloud identity infrastructure. Internal documents reviewed by researchers describe a workflow in which victims are directed to spoofed enrollment screens that mimic Microsoft's legitimate passkey registration flow. Engineers close to the incident response effort say the fake prompts capture the authentication handshake rather than a password, allowing attackers to register their own device as a trusted authenticator. Once that registration completes, the attacker holds a persistent foothold that survives routine password resets.

The timing is not accidental. Microsoft has been pushing passkey adoption across Entra ID and consumer accounts throughout 2026, and the rollout has been anything but smooth. Administrators have complained about inconsistent enrollment prompts, unclear fallback behavior, and help-desk confusion, all of which give social engineering campaigns room to operate. A forged prompt arriving during a genuine migration window is far harder for an employee to question.

What makes this story significant is the inversion it represents. Passkeys were marketed as phishing-resistant because the private key never leaves the device. That property still holds. The weakness is the enrollment phase, where a user must be convinced to bind a new authenticator. Attackers have simply moved upstream to the moment of trust establishment.

Microsoft has not publicly confirmed the scope of the campaign, and the number of affected tenants remains unverified. Researchers say the activity appears targeted rather than mass-scale, with higher-education and healthcare organizations among the early reported victims. Attribution is unresolved, and no single threat group has been definitively linked.

Expect Microsoft to tighten enrollment verification in the coming weeks, likely through conditional access hardening and additional device attestation requirements. Administrators should treat unsolicited passkey prompts as hostile until proven otherwise, and audit existing authenticator registrations for entries they cannot explain. The uncomfortable lesson is that no authentication method is phishing-proof when the attacker controls the first conversation.

Source: https://x.com/TheHackersNews/status/2099079014849880541

Related Stories

More Technology →