Microsoft Entra Passkey Scam Steals Accounts

A new Microsoft Entra passkey scam targets Microsoft 365 users through phone-based social engineering. Attackers pretend to offer security assistance during the call. As a result, victims believe they must register a new passkey. They unknowingly approve attacker access to their accounts. Therefore, organizations face a higher risk of data theft and extortion.

How the Scam Begins

Researchers found that attackers first contact victims by phone. They claim a security update requires a new passkey registration. Therefore, many users trust the request. The attackers then direct victims to a fake login website. The page closely resembles the real Microsoft enrollment process.

Victims enter their usernames and passwords on the fake website. However, the information goes directly to the attackers. The attackers immediately use the stolen credentials to access the real sign-in page. Meanwhile, victims continue following fake instructions. As a result, the attack progresses without raising suspicion.

Attackers Guide Victims Through Every Step

The phishing website adapts to each user’s authentication method. For example, it requests one-time passwords or approval notifications. Therefore, victims provide every security code needed for account access. The attackers control the process in real time. They adjust each screen based on the user’s responses.

Once the attackers complete the login process, they begin the fake passkey registration. Victims believe they are improving account security. However, the attackers register their own passkey instead. As a result, they gain long-term access to the account. The victim often remains unaware of the compromise.

Fake Passkey Registration Creates Lasting Access

The phishing pages imitate the real passkey setup process. They also display Microsoft-style branding and familiar instructions. Therefore, many users see no obvious warning signs. During the process, victims receive a fake recovery phrase. This step distracts them while attackers complete the enrollment.

Researchers explained that the recovery phrase serves no legitimate purpose. Instead, it keeps victims focused on unnecessary tasks. Meanwhile, attackers finish linking their own authentication method. As a result, they can access the account again without stealing another password. This technique makes the attack especially dangerous.

Multiple Industries Face the Threat

Researchers observed attacks against several industries. These include technology, healthcare, manufacturing, aviation, construction, and food services. Therefore, no single sector faces the risk alone. Any organization using Microsoft 365 could become a target. Security awareness remains essential across every business.

Attackers also rely on convincing conversations instead of technical exploits. For example, they pressure victims to act quickly during phone calls. However, careful verification can stop many attacks. Users should always confirm unexpected security requests. Simple precautions often prevent account compromise.

Why This Attack Matters

The scam abuses growing interest in passkey authentication. Instead of breaking security, attackers manipulate trusted users. Therefore, human error becomes the weakest point. The attack also demonstrates how phishing continues to evolve. Organizations should prepare for increasingly realistic social engineering campaigns.

Researchers expect similar techniques to spread further. Criminal groups continue improving phishing methods and account takeover tactics. However, security training and monitoring remain effective defenses. Early detection limits the damage after compromised accounts appear. Strong identity protection also reduces long-term risk.

How to Prevent Microsoft Entra Passkey Scam

Organizations should verify every unexpected security request before approving authentication changes. They should also educate employees about voice phishing and fake passkey enrollment pages. Furthermore, managed identity protection and endpoint detection services can quickly detect suspicious login activity and unauthorized account changes.

In addition, continuous security monitoring and rapid incident response help contain compromised accounts before attackers steal sensitive business data.

Sleep well, we got you covered.

Scroll to Top