All Articles

Cyber Security · September 2026

Passkey phishing: What to watch after someone signs in

Attackers are using fake passkey update messages to get into Microsoft 365, then staying for days. Here's what changes once they're already inside.

A new phishing campaign uses passkey and multi-factor authentication update messages to trick people into handing over access to their Microsoft 365 accounts. The part that matters for your business isn't the initial trick. It's what happens afterward: attackers add their own login methods, map your environment, and collect files over several days. If your security stops at the front door, you won't see any of it.

Why attackers are staying longer after they get in

The attackers in this campaign call or text employees pretending to be IT support. They say your passkey, multi-factor authentication, or single sign-on needs an update and walk the target through steps that grant access. Once inside a Microsoft 365 account, they don't grab files and leave. They add authentication methods they control so they can come back anytime. Then they explore.

They look at who has access to what. They find where important files live. They move through SharePoint, OneDrive, email, and other applications your team uses every day. The activity looks normal because they're using the same tools your employees use. A successful sign-in, then a settings change, then some searching, then file downloads. Individually, none of it sets off alarms.

That's the problem. By the time you notice something is wrong, they've been inside for days.

What this looks like in a business that uses Microsoft 365

If you're running Microsoft 365 for email, file storage, and collaboration, your environment has dozens of legitimate reasons for someone to sign in, change a setting, search for a document, or download a file. Employees do all of those things constantly.

An attacker doing the same things won't stand out unless you're comparing behavior across events. One person signing in from a new device isn't suspicious. That same person immediately changing authentication settings, then searching SharePoint for financial records, then downloading everything they found is suspicious. But only if you can see all three events together and understand the sequence.

Most businesses see individual logs. They don't see the story those logs tell when you line them up. That's where account takeover detection and continuous monitoring after sign-in become necessary. The question stops being whether someone got in and starts being what they're doing now that they're inside.

What you should do on Monday

Start by making sure your team knows what a real IT request looks like. If you have a process for authentication changes, document it and tell everyone. If someone calls or texts claiming to be from IT and asking them to update security settings, they should verify through a separate channel before doing anything. A quick message to your actual IT contact stops most of these attacks cold.

Next, check whether you have visibility into what happens after someone signs into Microsoft 365. Can you see when authentication methods are added? Can you spot unusual mailbox or file access? Can you connect those events to understand whether they're part of normal work or part of an attack in progress? If the answer is no, you need to fix that gap. Strong passwords and multi-factor authentication are still important, but they don't help once someone is already authenticated.

Finally, talk to whoever manages your Microsoft 365 environment about account takeover detection and post-delivery email security. These tools watch for compromised accounts that start sending phishing emails, unusual data access, or suspicious changes to user settings. They work after prevention fails, which is exactly when you need them most.

What's not worth worrying about

This campaign does not mean passkeys are unsafe. Passkeys remain one of the strongest authentication options available. Attackers are using passkey update messages as bait because people trust the concept, not because the technology itself is broken.

You also don't need to panic if your business is small and you're not handling sensitive government contracts or financial data. These attackers are patient and methodical because they're looking for specific information that takes time to locate. If you're a law firm, accounting practice, medical office, or any business with confidential client files, this campaign should get your attention. If you're running a retail shop or a trades business with straightforward operations, your risk profile is different.

The honest answer is that most Ontario businesses using Microsoft 365 already have some of the pieces in place. What's often missing is the layer that watches what happens after authentication. That's the gap this campaign exposes, and it's the one worth closing.

Why identity compromise is now a cloud security problem

For years, email security meant keeping malicious messages out of inboxes. That's still part of the job, but it's not the whole job anymore. Once an attacker controls a Microsoft 365 account, they're not just reading email. They're inside your collaboration tools, your file storage, your internal communications, and your business processes.

At that point you're dealing with a cloud security incident, not a phishing event. The attacker has access to everything that account can touch, and they'll use it to move deeper into your environment. Stopping them requires visibility across identity, email, applications, and data activity. It requires understanding that the compromise isn't the end of the attack. It's the beginning.

If your security approach still treats email and identity as separate problems, this is a good reason to reconsider. Modern attacks don't stay in one place. Your defenses shouldn't either.

Sources

See our security services

Get started today

Have an IT Question?

Our team is ready to help, whether you need advice on cybersecurity, cloud strategy, or AI readiness.