← All articles

Fake IT Helpdesk Calls Are Hijacking Microsoft 365 — Passkey Lures

Microsoft warns of helpdesk-impersonation attacks that steal M365 sessions with fake passkey/MFA updates. What South Texas and remote SMBs should do this week.

  • cybersecurity
  • microsoft-365
  • mfa
  • phishing
  • msp
  • smb

Attackers are not breaking Microsoft 365 with a clever zero-day. They are calling or texting employees, pretending to be IT helpdesk, and walking them into a fake “passkey” or MFA update. Microsoft Security Research says this pattern has been active since May 2026 — and it ends with attacker-controlled MFA, Graph recon, and file/mail theft.

What’s new

Microsoft’s September 9, 2026 security blog tracks passkey-, MFA-, and SSO-themed social engineering that leads to identity and cloud compromise. The opener is usually a phone call or SMS to a personal number: “Your passkey/MFA/SSO must be updated now or access will break.” Victims land on lookalike Microsoft sign-in pages. Despite the passkey story, the real goal is often adversary-in-the-middle (AiTM) phishing or device-code flows that capture sessions — then the actor registers their own MFA method for persistence. After that, Microsoft Graph reconnaissance and high-volume SharePoint, OneDrive, and Exchange access follow. (Microsoft Security Blog)

In some cases, compromised accounts are reused to push the same lure over Microsoft Teams, which raises click-through because the message looks internal.

Why Helotes & San Antonio SMBs should care

South Texas medical, finance, professional, and multi-site firms live in Microsoft 365. One successful helpdesk impersonation can expose patient or client files in SharePoint, shared drives in OneDrive, and mailbox history — without a malware alert on the company laptop if the employee opened the link on a personal phone.

Remote-managed SMBs nationwide face the same identity risk: if MFA enrollment and device-code flows are wide open, a convincing “IT called me” story is enough.

Practical next steps (this week)

  1. Train the helpdesk test — Real IT will never cold-call or text a personal phone asking you to enroll a passkey or MFA via a link. Hang up, call your known IT number, and verify before clicking anything.
  2. Lock MFA registration — Use Conditional Access so security-info registration requires phishing-resistant MFA, managed devices and/or named locations, and blocks high-risk sign-ins from adding new methods.
  3. Prefer phishing-resistant MFA — Push FIDO2/passkeys or Windows Hello for Business for admins and high-value users; treat SMS/voice OTP as temporary only.
  4. Block device-code flow (unless you have a documented need) — Device-code phishing is a common follow-on after the passkey lure.
  5. Hunt for unauthorized MFA and Graph noise — Alert on new authenticator/phone methods after unusual sign-ins; watch Graph enumeration of users/sites plus burst SharePoint/OneDrive downloads or Exchange REST access. On confirmation: revoke sessions, reset credentials, remove attacker MFA methods, and re-enroll securely.

For South Texas teams on-site: walk the floor (or Teams) this week — confirm nobody “updated MFA for IT” after an unexpected call, and verify cameras/guest Wi‑Fi stay segmented from the M365-joined network. For remote-managed clients nationwide: ask your MSP for a one-page check — MFA registration policy, device-code status, and last 7 days of auth-method changes.

Nice2GeekYou supports Helotes & San Antonio on-site work (Fiber, Cat6, cameras, racks) and remote MSP clients across the U.S. with the same foundation: identity hygiene first, then the wiring and monitoring that keep the business running.

Sources: Microsoft Security Blog — Passkey-themed social engineering