A security upgrade. Or an account takeover?
“Your account needs a passkey update.” A helpful-sounding caller, an urgent deadline and a familiar sign-in screen can make the wrong request feel routine.
Microsoft’s September 2026 investigation describes fake support calls and messages using passkey setup as a cover for phishing or device-code abuse. Attackers then added authentication methods and explored cloud data.
The trap is the request, not a broken passkey. Genuine passkeys remain phishing-resistant. Not all MFA methods offer the same protection.

Average self-reported cybercrime cost per small-business report.
Australia, FY2024-25 · ASDOf incidents observed by Coalition involved email compromise or funds-transfer fraud.
Global policyholders, 2025 · CoalitionCybercrime reports made to Australian law enforcement through ReportCyber.
Australia, FY2024-25 · ASDThese are broader cybercrime and insurance figures, not passkey-scam rates. Explore the full facts library.
A real Microsoft page can still be part of the trick
Device-code authentication is a legitimate way to sign in on devices with limited input. But entering a code supplied by an attacker can authorise their session, even on a genuine Microsoft page.
In the reported intrusions, attackers used Microsoft Graph to discover information and collect SharePoint, OneDrive and sometimes Exchange data. The observed paths varied; not every victim went through an identical sequence.
For staff: stop the unexpected conversation and contact IT through your established support number. Do not use the number or link supplied by the caller.

Three controls worth checking with your IT team
1. Close unused sign-in routes
Allow device-code authentication only where the business actually needs it.
What should IT check?
Review sign-in logs, test Conditional Access in report-only mode and document legitimate exceptions. Authentication-transfer flows need their own review.
Microsoft’s flow controls2. Protect enrolment too
Review who can register a new authentication method, from which devices and under what conditions.
What should IT check?
Use Conditional Access for security-information registration. Plan safe onboarding, lost-device recovery and emergency access. Require phishing-resistant authentication for sensitive and privileged access where supported.
Microsoft’s registration guidance3. Connect the warning signs
Review unusual sign-ins alongside newly added methods and abnormal cloud downloads.
What should IT check?
Check available logging, licensing and response ownership. A single API call or download is not proof of an attack; the sequence and user context matter.
Microsoft’s investigationSources & further reading
Microsoft Security Research: passkey-themed social engineering, 9 September 2026
Microsoft: authentication strengths · Authentication flows · Security-information registration
For a practical next step, explore identity and access security and security awareness training. General information; controls depend on your environment and Microsoft licensing.
Make your Microsoft 365 sign-ins harder to exploit
Explore ITFR’s cloud security services for identities, email, collaboration and ongoing oversight.









