Passkey-Themed Social Engineering Lures Attempt to Compromise Identity and Cloud Platforms

Executive Summary

Microsoft Security Research published in a report  on 9 September 2026 tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs.

The activity begins with identity-focused social engineering and impersonation infrastructure, proceeds through authentication persistence and cloud reconnaissance, and is followed by targeted data access and activity consistent with data collection and potential exfiltration. Microsoft Threat Intelligence assesses that the initial access activity observed in this campaign is used by a range of threat actors, including Storm-3121, Storm-3032, and others.

Per Microsoft, defenders should investigate this sequence across identity, Microsoft Graph, SharePoint, OneDrive, and Exchange signals, then revoke sessions and remove unauthorized authentication methods for confirmed compromises.

Key Takeaways

The attack often begins with a seemingly routine call or message on a user’s personal phone number from someone claiming to be from the organization’s IT helpdesk. The passkey narrative serves as a pretext to guide victims through adversary-in-the-middle phishing or device-code authentication flows.

Following initial access, the actor’s first objective was to transform a temporary compromise into a persistent foothold. The actor enrolled an MFA method under their control, typically by registering a new phone number, authenticator application, or software-based one-time password token.

Once MFA persistence was established, the actor initiated an extensive internal reconnaissance phase using Microsoft Graph to inventory users, groups, permissions, resources, and accessible content across the tenant with the compromised identity.

Following reconnaissance, the actor transitioned into large-scale data collection across Microsoft 365 workloads using the compromised identities. Across SharePoint and OneDrive, the activity generated significant volumes of FileAccessed and FileDownloaded events, indicating systematic retrieval of cloud-hosted documents and organizational data.

Per Microsoft, organizations should enforce phishing-resistant MFA via Conditional Access. Defenders should also enforce Conditional Access that requires a managed, compliant device for Exchange, SharePoint, and Graph-privileged apps.

Indicators of Compromise

Microsoft has provided Indicators of Compromise included with this campaign, which are included below:

Indicators

Type

Description

passkeyhelpdesk[.]com

Domains

Passkey support lure

secure-passkey[.]com

Domains

Passkey security

setupmypasskey[.]com

Domains

Passkey setup

add-passkey[.]com

Domains

Passkey enrollment

integratedsso[.]com

Domains

SSO

oktasession[.]com

Domains

Identity-provider session

keysyncos[.]com

Domains

Key synchronization

oskeysync[.]com

Domains

Key synchronization

oskeysetup[.]com

Domains

Key setup

oskeyregister[.]com

Domains

Key registration

syncmykey[.]com

Domains

Key synchronization

myconnectkey[.]com

Domains

Key connection

oskeyconnect[.]com

Domains

Key connection

validationsetupac[.]com

Domains

Account validation and setup

portalsetuphub[.]com

Domains

Portal setup

More Recent Blog Posts

Executive Summary Arctic Wolf is tracking a widespread data theft and extortion threat cluster designated as PREY-0058, also known as Cordial Spider and...

Executive Summary A dark web marketplace is selling 153,000,000 American and Canadian driver’s licenses, reportedly siphoned from idscan[.]net, according to multiple social media...

Executive Summary On 28 August 2026, Microsoft Threat intelligence reported details of what they have dubbed a TerminalFix campaign, a variant of ClickFix,...