New Phishing Tactics Exploit Corporate Shift to Passwordless Microsoft 365 Security

Cybersecurity attackers are currently weaponizing the corporate transition to passwordless authentication, using the rollout of passkey technology as a lure to infiltrate Microsoft 365 environments. According to a security report released by Microsoft on September 9, 2026, threat actors are deploying sophisticated social engineering campaigns to steal session tokens and exfiltrate sensitive data from SharePoint Online, OneDrive for Business, and Exchange Online.

The timing of these attacks is no coincidence. In August 2026, Microsoft announced that passkeys would become the default sign-in method for Entra ID (formerly Azure AD) starting in September 2026. This industry-wide shift has created a window of opportunity for attackers to exploit employee confusion during the transition period. While passkeys themselves remain a significantly more secure alternative to traditional passwords, the human process of enrolling and migrating to the new standard has become a primary target for extortion groups.

How the “Security Paradox” Functions

The campaign, which has been active since at least May 2026, relies on a “Security Paradox”: as organizations deploy more robust security measures, attackers move “left” in the process, targeting users before the protection is fully established. Rather than attempting to crack a passkey’s cryptographic private key—which is virtually impossible with current methods—attackers trick users into handing over access through legacy phishing techniques disguised as security upgrades.

Security researchers at Arctic Wolf are tracking a specific threat cluster involved in this activity under the moniker PREY-0058. This group and others utilize a combination of voice phishing (vishing) and SMS messages, frequently targeting employees’ personal mobile phone numbers. By contacting users on personal devices, attackers effectively bypass corporate endpoint monitoring and security filters that would typically catch malicious links on managed laptops or desktop computers.

Conceptual graphic of an SMS phishing lure and a bypassed padlock.
Vishing and SMS lures targeting personal devices are being used to bypass corporate endpoint monitoring.

Technical Execution and Evasion

The attacks do not rely on traditional credential harvesting. Instead, they use one of two primary methods to gain access to corporate accounts:

  • Adversary-in-the-Middle (AitM): Attackers direct users to proxy sites that mirror the legitimate Microsoft login page. When the user attempts to “register” their passkey, the proxy captures the session token, allowing the attacker to bypass Multi-Factor Authentication (MFA) entirely.
  • Device-Code Phishing: In this flow, the attacker provides the victim with a code and directs them to a legitimate Microsoft device-pairing URL. If the victim enters the code, they unknowingly authorize the attacker’s device to access their corporate account.

Arctic Wolf has identified several domains used in these campaigns designed to mimic official IT portals, including assignpasskey[.]com and mfaregister[.]com. These sites are often presented to high-level executives or employees with elevated permissions to maximize the value of the stolen data.

Detecting the Lure

Because these attacks target the user’s perception of security, distinguishing a legitimate passkey enrollment prompt from a phishing attempt is critical. Microsoft and security analysts note several red flags that characterize these campaigns:

Legitimate passkey prompts for Entra ID will typically occur within the browser during a standard login flow on a known corporate domain, such as login.microsoftonline.com. Any request to register a passkey that originates from an unsolicited SMS or a phone call to a personal device should be treated as highly suspicious. Furthermore, legitimate IT departments rarely require users to navigate to third-party domains like “assignpasskey” to complete security upgrades.

Once an attacker successfully captures a session, they often move quickly to exfiltrate data. Organizations are advised to monitor for unusual “Risky Sign-in” logs in Entra ID, specifically those originating from unfamiliar ISP ranges or those that involve the successful use of a device-code flow from an unexpected geographic location.

More From Category

More Stories Today