Passkey social engineering hacks are seeing a spike in identity and cloud compromises, which the Microsoft Security Research team have monitored and reported amid a lot of unusual sign-ins. The sequence of hacker activity started with a flurry of unusual sign-ins on cloud based accounts, followed by bad actor-added authentication methods.
The activity employed social engineering and and impersonation techniques persistently throughout the authentication phase and was consistent with targeted data capture from compromised cloud infrastructure. The persistence of data and content discovery warranted investigation from Microsoft.
To provide an overview of the attack sequence, Microsoft observed the identity compromises from the initial identification of target organisations to vishing and taking control of the victim’s identity. When the session was compromised, attackers could gain access to the personal sign-ins security portal and input the attacker’s manipulated authentication information. A high volume of data was collected and extracted.
An attack typically begins with a call from an unknown number claiming to be from someone working at Microsoft’s IT desktop, which guides the unassuming user through a single sign-on (SSO) or MFA reconfiguration to deviate from the real trap: adversary-in-the-middle (AiTM) phishing or device-code authentication flows. In this scenario, the actor can compromise session data and credentials.
Identity Week Europe is the place to meet corporate organisations and top vendors who want to work collaboratively to solve IAM challenges driven by modern fraud threats such as social engineering techniques.














