Navigation
  • SEARCH HERE
  • SOLUTIONS
    • Information Security Solutions
      • Enterprise Application Security Solutions in Asia
      • Network & Infrastructure Security Solutions
      • Zero Trust Security
      • Security Information and Event Management
      • Remote Monitoring & Management (RMM)
      • File Integrity Management
      • Systems Administration Tools
      • Data Loss Prevention
      • Data / Password Recovery
      • IT Management Solution Offering | Distributor in Asia
      • Identity and Access Management Solution Offering | Distributor in Asia
      • Employee Activity Monitoring (EAM)
      • Digital Forensic Investigation
    • Software Development Solutions
      • Integrated Development Environments
      • Development Components
        • UI Tools
        • Networking Components
        • Office Components
        • Barcode Components
        • Communication Components
      • Imaging Solutions
      • Software Localization
      • Release Automation & Management
      • eLearning Authoring Solutions
      • Charting Solutions
      • PDF Solutions
      • Reporting Solutions
      • Testing & QA
      • Text Retrieval / Enterprise Search
      • Database
  • Services
    • Live Solution Walkthroughs
    • Implementation Services
    • Best Practices Consulting
    • Pre-Sales and Post-Sales Services
  • What's New
    • Our Event
    • Our Blogs
    • Special Offers
  • About
    • About LOGON Software Asia
    • Our Partnership
  • Publishers - Join our network
  • Resellers - Expand your portfolio
Site logo
  • Solutions
    • Information Security Solutions
      • Identity and Access Management
        • Privileged Access Management (PAM)
        • Multi-Factor Authentication (MFA)
        • Identification Verification (IV)
        • Self-Service Password Reset (SSPR)
      • Network & Infrastructure Security
        • DDoS Mitigation and Protection
        • Digital Forensic Investigation
        • Malware Detection & Analysis
        • Network Monitoring Software
        • Email Security
        • Log Monitoring
      • Endpoint & Device Security
        • Patch Management
        • Remote Monitoring & Management (RMM)
        • Employee Activity Monitoring (EAM)
        • Mobile Device Management (MDM)
      • IT Management
        • IT Service Management
        • IT Asset Management
        • Software Asset Management
        • Hardware Asset Management
        • Software License Management
        • Systems Administration Tools
      • Application Security
        • Development Security | Shift Left AppSec | SAST, SCA, IAST
        • Runtime Protection Solutions | DAST, RASP, WAF, Container Security
        • Strategic Management Solutions | ASPM, MAST, VAPT
      • Data Security
        • Data Loss Prevention
        • File Integrity Management
        • Data / Password Recovery
        • Data Security Posture Management
      • Cloud Security
        • Cloud Security Posture Management
        • Cloud Work Protection
      • External Attack Surface Management
        • Cyber Threat Intelligence
        • Third Party Risk Management
      • Security Operations & Incident Management
        • Security Information and Event Management
        • Security Orchestration, Automation and Response (SOAR)
      • Zero Trust Security
    • Software Development Solutions
      • Integrated Development Environments
      • Imaging Solutions
      • UI Tools
      • Charting Solutions
      • Database
      • Networking Components
      • Office Components
      • Barcode Components
      • Release Automation & Management
      • Software Localization
      • Communication Components
      • Automated Testing
      • eLearning Authoring Solutions
      • Reporting Solutions
      • Text Retrieval / Enterprise Search
      • Testing & QA
  • Services
        • Live Walkthrough Sessions

          Experience the full feature of our key solutions through live platform

          View All Sessions >
        • Implementation Services
        • Pre-Sales and Post-Sales Services
        • Best Practices Consulting
  • Partners
    • Our Partners
    • Partner with LOGON Today!
      • Vendors - Join Our Network
      • Resellers - Expand Your Portfolio
      • Procurement Managers
  • Resources
        • ABOUT US

        • About Us
        • Our Locations
        • Careers@LOGON - We are hiring !
        • DISCOVER

        • Our BlogsNEW BLOGS
        • Our EventsJOIN UPCOMING EVENTS
        • LOGON to CyberSecurity PodcastNEW EPISODES
        • GET HELP

        • Contact Us
        • Help Desk
        • Request a Demo
        • Request a Quote
        • COMPLIANCE

        • 🇭🇰 Hong Kong PDPO
        • 🇮🇳 India DPDP Act
        • 🇸🇬 Singapore PDPA
        • 🇹🇭 Thailand PDPA
  • More results...

View large
Blog, Cloud Security Blog, Identity and Access Management Blog, LOGON Blog

When Passkeys Become the Bait: A New Wave of Voice Phishing Targeting Microsoft 365

LOGON BLOG

When Passkeys Become the Bait:

A New Wave of Voice Phishing Targeting Microsoft 365

microsoft passkey phishing

Author: Sandy Chu, LOGON Software Asia

Your users have passkeys. Your Conditional Access policies are in place. Your MFA coverage looks solid on paper.

So why are attackers still walking out with valid Microsoft 365 sessions?

Because they stopped attacking your technology. They started attacking your people—and the processes around them.

Since May 2026, Microsoft Security Research has tracked a wave of attacks that bypass passkeys entirely. No cryptography was broken. No private keys were extracted. Instead, attackers call your employees, impersonate IT support, and create enough urgency that the victim willingly completes an authentication action—one that authorizes the attacker, not themselves.


The 60-Second Version

What attackers do: Impersonate IT support by phone, text, or Microsoft Teams.

What they say: “You need to register your passkey immediately” or “Your MFA needs updating, or you’ll lose access.”

What actually happens: The victim authenticates on a lookalike page or enters a device code on Microsoft’s real login page. Either way, the attacker gets a valid session.

What comes next: The attacker maps your environment with Microsoft Graph, registers their own MFA method for persistence, then slowly exfiltrates files and emails—often fewer than 1,000 items per hour to avoid detection.

Who’s behind it: Data-extortion clusters including Storm-3121 and Storm-3032, linked to ShinyHunters, BlackFile, and Helix. Google tracks overlapping activity as UNC6671.

Five-step passkey-themed phishing attack chain from reconnaissance to account compromise

Why Your Passkeys Didn’t Stop This

Here’s the part that catches people off guard.

Passkeys are genuinely strong. They’re cryptographically bound to the legitimate website’s domain. The private key never leaves the user’s device. They’re phishing-resistant by design.

But attackers found two ways around them:

 

Technique 1: Adversary-in-the-Middle (AiTM)

The attacker positions a malicious server between your user and Microsoft’s real authentication service. If the user falls back to a weaker method—an SMS code, an app-generated OTP, or a push approval—the attacker relays it in real time and captures the session token.

The key insight: Attackers don’t need to break your strongest method. They just need to convince your user to use a weaker one.

 

Technique 2: Device-Code Abuse

This one is clever. Microsoft’s OAuth device-code flow exists for legitimate reasons—devices where typing credentials is difficult. The attacker initiates an authentication request from a client they control, generates a code, and tells the victim to enter it on Microsoft’s real login page.

Here’s the problem: the page is genuinely Microsoft’s. The URL is correct. The certificate is valid. Everything looks right.

But entering that code authorizes the attacker’s client, not the employee’s passkey.

The key insight: Blocking lookalike domains won’t help here. The victim is on a legitimate Microsoft page.


What Happens After the Attacker Gets In

In one case Microsoft examined, the attacker signed in from an unmanaged device. Within minutes, the session was accessing My Apps, My Profile, Microsoft Approval Management, and My Sign-Ins. From there: SharePoint Online, Outlook on the web, and internal business applications.

The session stayed active for about an hour while the attacker mapped what was available.

And if your Entra ID is your central SSO platform? The blast radius extends well beyond one inbox. Depending on the user’s permissions, attackers may reach Salesforce, Google Workspace, Dropbox, Slack, SAP, Adobe, Zendesk, Atlassian, and your internally developed applications.

 

Persistence: The Part That Ruins Your Weekend

Attackers don’t just grab and go. They register their own authentication methods—phone numbers, authenticator apps, software tokens—so they can come back later.

This means a password reset alone won’t remove their access. Neither will killing a single browser session. You need to review the entire identity: registered authentication methods, active sessions, refresh tokens, OAuth grants, mailbox rules, device registrations, and enterprise application permissions.

Miss one, and the attacker still has a way back in.

 

Low-and-Slow Data Theft

Attackers aren’t always smash-and-grab. Microsoft observed collection continuing for hours or days, generally accessing fewer than 1,000 files or emails per hour.

Why? Because it blends in. Volume-based detection rules won’t catch it. Your normal business traffic looks similar.

But over time, that’s a lot of documents and emails—especially if the compromised user has access to shared repositories or departmental mailboxes.


Why this matters to Enterprises in Asia

1. Hybrid IT creates blind spots

Many enterprises in Asia run on-prem Active Directory alongside Microsoft 365 or Entra ID. Different authentication flows, different teams, different views. Help desk staff often can’t tell whether a “passkey registration request” is legitimate.

2. Multilingual social engineering is more convincing

Attackers can conduct voice phishing in local languages, mimicking local IT support teams. When the message comes through Microsoft Teams from what looks like an internal account, it’s even harder to question.

3. BYOD is the norm

Your employees handle corporate authentication on personal phones outside MDM control. Phishing links sent there bypass your email gateways and endpoint protection entirely.


What LOGON Brings to the Table

At LOGON Software Asia, we help organizations close the process gaps that social engineering exploits—without slowing down your passwordless journey.

We approach this problem across four pillars.

1. Identity and Access Management Architecture

Built for complex Asian enterprise environments. Covers Windows logon (including offline), RDP and privileged sessions, VPN access, on-prem AD and multi-forest environments, hybrid cloud directories, and legacy systems that can’t be modernized.

What this means for you: Identity security controls extend beyond the cloud login page to every identity use case across your network.

2. AI-driven Social Engineering Simulation

Our solutions let you test your frontline against the exact techniques in this blog—not just email phishing, but AI-generated voice calls (vishing), SMS phishing (smishing), and deepfake-enabled scenarios.

What this means for you: An employee who has already received a convincing fake IT call—and learned to verify it through a trusted channel—is far less likely to fall for the real thing.

3. Self-Service Password Reset

Most users can help themselves when they’re locked out—if you give them the tools. Our self-service password reset capabilities handle password reset, account unlocks, and Temporary Access Pass issuance for Active Directory, cloud identity providers, and application-level systems like SAP, Oracle, and IBM.

What this means for you: Fewer calls to the help desk. Organizations typically see an 85% or greater reduction in password reset calls after deploying self-service.

4. Verified Help Desk Assistance

Authentication proves a device. It doesn’t prove a person. Our solution offers verified help desk assistance that makes the verification decision inside the ticket your agent is already working in—using contextual signals and configurable soft tokens. The agent facilitates, but never overrides the outcome. That produces a defensible, auditable result instead of a judgment call.

What this means for you: An attacker who can convince your support agent to reset MFA has bypassed every technical control you’ve deployed. Verified workflows ensure high-risk changes require proof of identity—not just a convincing phone manner.

5. Cloud Workload Protection (CWPP)

Real-time monitoring of cloud workloads with machine learning-based threat detection. When an account accesses SharePoint or OneDrive at abnormal times or from abnormal locations, the system triggers alerts or blocks automatically—rather than waiting for an obvious download spike.

What this means for you: You catch low-and-slow data collection that volume-based rules miss.

6. Cloud Security Posture Management (CSPM)

Many organizations are exposed because Entra ID’s default settings are too permissive. Our CSPM capabilities assess configuration deviations across IaaS, SaaS, and PaaS—identifying missing Conditional Access policies, over-granted OAuth permissions, and providing remediation guidance.

What this means for you: You find and fix the configuration gaps attackers exploit before they find them.


The Bottom Line

Enterprise authentication is now an attack surface that extends far beyond the login page.

Passkeys remove one of the most phishable secrets—the password. But attackers have shifted their focus to enrolment workflows, fallback mechanisms, user trust, access tokens, and the cloud applications behind a successful sign-in. They’re targeting your help desk, your employees’ personal phones, and the processes you built to make passwordless authentication work.

The organizations that come out ahead will be the ones that secure the entire identity lifecycle—not just the login moment—and prepare their people for the calls, messages, and conversations designed to work around it.

LOGON Software Asia helps organizations across the region strengthen Microsoft 365 identity security and reduce human risk—whether you’re just beginning your passwordless journey or looking to harden an existing deployment.

Ready to secure your identity perimeter?

Contact LOGON Software Asia today. Let’s talk about where your gaps are—and how to close them.

Contact Us Today
Contact Us Today

FOLLOW US ON

  • LinkedIn
  • Facebook
  • Instagram
  • Twitter
  • YouTube
Read Next:
BlogCloud Security BlogIdentity and Access Management BlogLOGON Blog
When Passkeys Become the Bait: A New Wave of Voice Phishing Targeting Microsoft 365
BlogImmuniWeb Blog
ImmuniWeb Receives “AI-Enabled Penetration Testing” Accreditation by CREST
BlogRadiator Software Blog
Radiator 10.34 now available!

Privacy Policy Company Overview

COMPANY

Our Location Career with LOGON Our Partners

SERVICES

Training Services Implementation Services Pre-Sales and Post-Sales Services Best Practices Consulting

GET IN TOUCH

Phone:
Hong Kong: +852 2512 8491
India: +91 70220 22744 / +91 63668 26133
Email: [email protected] ©2025 LOGON International Ltd. All rights reserved
logon logo WHITE

Search engine

Use this form to find things you need on this site

More results...

Fill in the form below
  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form

Watch On-demand Webinar

  • This field is for validation purposes and should be left unchanged.

Get Your Free UserLock Trial

  • This field is for validation purposes and should be left unchanged.

Download Your Free Trial 10-Day Trial Today

  • Downloading and evaluating Smart Package Studio is quick and easy
  • Includes a short introductory guide that suggests smart features to try
  • Access the full functionality of Smart Package Studio during the trial
  • This field is for validation purposes and should be left unchanged.

Request for Priority Support with our support team

  • This field is for validation purposes and should be left unchanged.
  • Drop files here or
    Max. file size: 30 MB.

    Get Free Assessment of your Web Asset

    Request a free non-intrusive security assessment of your website. Get a report with an overview of client-side security risks.

    • This field is for validation purposes and should be left unchanged.
    • This field is hidden when viewing the form

    Recommend a Topic

    • This field is for validation purposes and should be left unchanged.

    Partner with Us on the next episode

    • This field is for validation purposes and should be left unchanged.

    Watch On-demand Webinar

    • This field is for validation purposes and should be left unchanged.
    Start PreCrime Network for Free

    Oops! We could not locate your form.

    Book a Free Demo Today

    Get Your Free Trial

    Oops! We could not locate your form.

    Get Your Free Trial
    • This field is for validation purposes and should be left unchanged.
    • This field is hidden when viewing the form
    • This field is hidden when viewing the form
    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form
    Request for Training Quote
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form