An urgent request to set up a passkey can sound like routine IT housekeeping. In a September 9, 2026 security investigation, Microsoft described attackers using that story to lure employees into sign-in traps and gain access to work accounts.
Microsoft says it has observed the broader pattern of cloud intrusions since May 2026. Its report describes compromised accounts, newly added authentication methods and activity across services including Microsoft Graph, SharePoint and OneDrive. The warning concerns attackers exploiting a familiar security task, not a finding that they have cracked passkeys.
The request may arrive as a call or text
According to Microsoft, an attacker may contact an employee on a personal phone while pretending to be the company’s IT helpdesk. The employee is told that a passkey or other sign-in setting needs an immediate update to avoid disruption. A link may lead to a page designed to resemble a Microsoft sign-in screen.
In some cases, attackers also send passkey-themed messages from an account they have already compromised. A request that appears to come through a familiar workplace channel can be persuasive, particularly when it names the employee’s organization. The apparent urgency is part of the deception.
What the attackers want instead of a passkey
Microsoft says enrolling a passkey is often not the attacker’s real objective. One route uses a fraudulent sign-in page to capture credentials or session tokens. Another persuades the employee to enter a device code on a genuine Microsoft authentication page, unknowingly granting an attacker-controlled application access.
That second route is easy to misunderstand because the page where the code is entered can be legitimate. The danger lies in who initiated the request and what the approval authorizes. Microsoft’s findings do not show that a real passkey was stolen or that its underlying authentication was defeated in these cases.
What can happen after the first sign-in
In the sequences Microsoft investigated, gaining access was sometimes followed by an attempt to keep it. Attackers added authentication methods under their control, such as a phone number or authenticator method, so they could satisfy later sign-in challenges. They then used the compromised identity to inspect available applications, users and cloud resources.
Microsoft also documented searches of files and mail, along with activity consistent with collecting data. It distinguishes that broader pattern from individual log entries: a request to access a document does not, on its own, prove that the document was downloaded. The sequence of sign-in, authentication changes and cloud activity is more informative than a single event.
Why passkey language makes a useful lure
Passkeys are becoming a more familiar part of signing in. In a May 2025 update, Microsoft said it was seeing nearly a million passkeys registered daily for Microsoft accounts and was making new consumer accounts passwordless by default. Those figures describe Microsoft’s reported position at that time; they do not measure this attack campaign or show that passkey adoption caused it.
The distinction matters for anyone receiving a setup request. An attacker can borrow the language of a genuine security improvement while directing someone into a different authentication flow. Seeing the word “passkey” in a message is not evidence that the request came from IT.
What to do with an unexpected setup request
If a call, text or workplace message asks you to change a sign-in method immediately, verify it through an IT contact or channel you already know. Do not rely on the phone number or link supplied in that message to confirm it. Be especially cautious if someone asks you to enter a device code or approve a sign-in you did not start.
Microsoft advises organizations investigating a suspected compromise to check for newly registered authentication methods and unusual cloud activity. For confirmed cases, its guidance includes revoking active sessions and removing unauthorized sign-in methods. For an employee, reporting the request promptly gives that investigation a starting point, even when the first contact happened on a personal phone.
The attack works by making a false instruction feel like an ordinary account-security task. Recognizing that request before approving a sign-in may prevent the attacker from getting the access they came for.