Sep 20 / Admin

New Scam Alert: Microsoft Warns of Passkey Phishing Attacks

Channel Insider reported:  

Microsoft warned Sept. 9 that attackers are using passkey-themed social engineering to trick users and compromise cloud identities. The campaigns can ultimately give attackers access to Microsoft 365 services including Exchange Online, SharePoint, OneDrive, and Microsoft Graph by manipulating authentication flows, stealing session tokens, or using previously compromised credentials.

Attackers impersonate IT support and contact employees with instructions to supposedly update or configure security features such as passkeys, multifactor authentication, or single sign-on.

Microsoft also observed attackers abusing device-code authentication, which can trick a user into authorizing an attacker-controlled session. 

Find the original article here.
 
Key Takeaway:  Setup a passphrase between departments, especially IT.  Change it periodically.  Ask for the passcode each time to confirm it's an IT team member and not a fraudster.

Enroll in Training Sessions:  Last Thursday of Every Month is Training on Frauds and New Scam Alerts and How to Combat
Click Image to Enlarge
Created with