✦ For YouGeopoliticsTechFinanceHealthEnergySportsCulture◆ SN Last Week★ Saved
📎 SkimNews has covered Microsoft 94+ times · see the file →

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data — SkimNews

By The Hacker News · Summarized & edited by · 2026-09-13
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Get the Tech newsletter

Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.

Why it matters: Passkey-themed social engineering defeats one of the strongest MFA safeguards: attackers who trick a user into approving a single sign-in can then enroll their own second factor, locking the real user out while retaining persistent access. With Graph-driven exfiltration spanning SharePoint, OneDrive, and Exchange—and activity correlating to ShinyHunters, Falcon, and Helix extortion brands—a single help-desk call can convert into multi-day data theft that looks like normal API traffic to network defenders.

Share this story

Ask SkimNews
More tech → Read original →

Get the Tech newsletter

Curated tech stories, every morning. Free.

No spam. Unsubscribe anytime.