UpTrajectory Review

Microsoft is warning that attackers have found a fresh angle on one of the oldest tricks in the book: impersonating the IT department. The new campaign, detailed in a TechRepublic report, uses fake passkey and multi-factor authentication update requests to phish employees, hijack their active sessions, and then move into Microsoft 365 data. The scam exploits a moment of transition. As companies push users away from passwords and toward passkeys, attackers are exploiting the confusion and urgency around migration, betting that an employee who sees a prompt to update their security settings will comply without a second thought.

For a small-business operator, this is not an abstract threat. If you run a lean team without a dedicated IT staff, your employees are likely managing their own credentials and MFA setups. They are also the ones most likely to receive a convincing-looking prompt to update a passkey or re-enroll a device. The stakes are high: a single compromised session can give an attacker access to your entire Microsoft 365 environment, including email, files, and any business data stored in SharePoint or OneDrive. For a business that relies on Microsoft 365 for daily operations, a breach can mean lost revenue, data exposure, and a painful recovery process.

What is genuinely new here is the weaponization of a security upgrade. Passkeys are supposed to be the future of authentication, and Microsoft has been pushing them hard. Attackers are now using that push as a pretext, turning a legitimate security improvement into a phishing lure. This is a classic case of social engineering adapting to new technology. The report suggests that attackers are not just stealing credentials; they are hijacking sessions, which means they can bypass MFA entirely by using an already authenticated session. That is a significant escalation, and it underscores why MFA alone is no longer a silver bullet.

The second-order effects are worth considering. If attackers can hijack sessions, then the traditional advice of just turn on MFA is no longer sufficient. Businesses need to think about session management, conditional access policies, and monitoring for anomalous login behavior. This also puts pressure on IT providers and managed service providers to educate their clients about the risks of phishing during security transitions. For small businesses that outsource IT, this is a reminder to ask your provider what they are doing to detect and respond to session hijacking, not just credential theft.

So what should you do? First, treat any unexpected prompt to update a passkey or MFA settings with suspicion. Verify it through a known, trusted channel, not by clicking a link in an email or message. Second, if you use Microsoft 365, review your security settings to ensure you have conditional access policies in place that can detect and block unusual sign-ins. Third, train your employees to recognize that security updates can be phishing lures, especially during periods of transition. Finally, watch for further guidance from Microsoft and security researchers on how these attacks are evolving. The shift to passkeys is necessary, but it will not be painless.

The bottom line is that attackers are getting better at exploiting the very tools we use to protect ourselves. Passkeys and MFA are still worth using, but they are not a set-and-forget solution. Small-business owners need to stay vigilant, educate their teams, and work with their IT providers to ensure they are not the next victim of a well-timed phishing scam.

“Microsoft warns attackers are using passkey and MFA update requests to phish employees, hijack sessions, and access Microsoft 365 data.” — TechRepublic

Takeaway: Treat unexpected passkey or MFA update prompts as phishing attempts and verify them through a separate, trusted channel before clicking anything.

Excerpt from the original — TechRepublic

Microsoft warns attackers are using passkey and MFA update requests to phish employees, hijack sessions, and access Microsoft 365 data.
The post Hackers Are Using Passkey Updates as a New Microsoft Phishing Hook appeared first on TechRepublic.