Microsoft 365 Users Targeted By Sneaky Voice Call Hacking Attack
By 813 Staff
The expectation was that passkeys would be a silver bullet for account security—phish-resistant by design, useless to attackers without the physical device. Instead, internal documents now circulating among Microsoft’s security teams reveal that threat actors have already weaponized a vishing campaign targeting the exact authentication method meant to replace passwords for Entra ID users. According to a report from BleepingComputer (@BleepinComputer), attackers are now tricking Microsoft 365 administrators into enrolling fraudulent passkeys, effectively handing over the keys to the kingdom.
The attack, first documented in late June 2026, combines social engineering with a technical twist. Engineers close to the project say callers pose as Microsoft support or internal IT staff, claiming the target’s account has triggered an alert for suspicious activity. The victim is instructed to visit a legitimate-looking portal—often a clone of the Microsoft Entra admin center—and complete a passkey registration flow under the guise of “re-securing” their account. In reality, the attacker records the enrollment handshake or, in more sophisticated variants, uses a relay tool to bind the passkey to the adversary’s controlled device. The rollout of this technique has been anything but smooth for defenders: Microsoft has already pushed multiple detection rule updates to Defender for Identity, but initial alerts were easily bypassed by using legitimate enrollment endpoints.
Why this matters for any organization running Entra ID is stark. Passkey enrollment for administrator accounts was designed to be the final line of defense—something the user possesses, not something an attacker can steal remotely. This campaign undermines that entire trust model. Once the attacker’s passkey is registered, they inherit all the privileges of the compromised admin, including the ability to reset other users’ credentials, modify conditional access policies, and exfiltrate mailbox data without triggering typical sign-in anomalies. The attack surface here isn’t the passkey protocol itself, but the human element and the lack of friction in the enrollment flow.
What comes next is uncertain but worrying. Microsoft has acknowledged the campaign in a private security advisory sent to enterprise customers earlier this week, though a public advisory has not yet been issued. Sources familiar with the company’s response roadmap say a mandatory admin notification prompt during enrollment is being fast-tracked for July’s patch cycle. Until then, organizations should treat any unsolicited call requesting passkey enrollment as hostile and require a confirmed out-of-band verification before any new registration is allowed.
Source: https://x.com/BleepinComputer/status/2074898230526054826

