All Articles

Cyber Security · September 2026

Why your team is getting fake IT calls about passkeys

Attackers are calling employees directly, pretending to be IT support and asking them to update passkeys or MFA. Once someone follows the link, the attacker can stay in your email and files for weeks.

If one of your staff gets a call or text on their personal phone from someone claiming to be IT support, asking them to update a passkey or fix their multifactor authentication right away, that call is probably not from your IT team. Attackers have been using this approach since May 2026 to get into cloud email, file storage, and business records. The tactic works because it sounds routine, arrives on a personal device where your security tools cannot see it, and moves quickly enough that most people do not stop to verify.

What happens when someone clicks the link

The link usually goes to a page that looks like a Microsoft sign-in screen. The attacker captures the login, approves the authentication on their own device, and then adds a second phone number or authenticator app to the account. That second factor belongs to them, not your employee.

Once that is done, they can sign in again whenever they want. They start by listing users, groups, and permissions. Then they search through SharePoint, OneDrive, and email using automated scripts. In several cases, attackers used the python-httpx tool to download large volumes of files and messages. The whole sequence can happen in under an hour, and the employee may not know anything went wrong until someone notices unusual sign-ins or missing files.

Why this is harder to catch than a normal phishing email

Most phishing comes through work email, where filtering and link protection can block it. This attack starts on a personal phone with a call or SMS. If the employee opens the link on their own device, your endpoint protection does not see it. The only early clue is usually the employee remembering the call after the fact.

The attacker also rotates domains quickly. They register names like company-name.secure-passkey.com or company-name.integratedsso.com, often through Nicenic registrar, and have them running within hours. By the time you block one, they have registered another. The constant changing of infrastructure means you cannot rely on a static blocklist.

What to look for in your logs

If this has already happened, you will see a few clear patterns. Look for new phone numbers or authenticator apps added to user accounts. Check for sign-ins from unmanaged devices followed immediately by access to My Sign-Ins, My Apps, or Microsoft Approval Management. Watch for high volumes of Microsoft Graph API calls from a single account, especially requests that walk through users, groups, SharePoint sites, OneDrive folders, and mailboxes in quick succession.

Large numbers of FileAccessed and FileDownloaded events in SharePoint or OneDrive are another strong signal, particularly if the user agent is something like python-httpx or if the activity happens outside normal working hours. Any account that suddenly starts searching across multiple repositories and then retrieves email attachments or file content should be investigated right away.

What to do if you think someone clicked

First, revoke all active sessions for the affected account. Then remove any authentication methods that were added recently and that the employee does not recognise. Reset the password and require the user to register their own MFA device again, in person or over a verified call.

Next, review sign-in logs and Microsoft Graph activity for that account over the past few weeks. If you see sustained reconnaissance or file downloads, assume the attacker had time to collect data. You may need to notify clients, partners, or regulators depending on what was accessed. If your team does not have the logging or tools to investigate this properly, bring in someone who does.

What this means for your IT policy on Monday

Tell your team that real IT support will never call or text their personal phone asking them to click a link and update authentication. If they get that call, they should hang up and contact your actual IT provider or internal IT person directly using a number they already have.

Turn on phishing-resistant MFA if you have not already. Passkeys and hardware tokens stop this attack cold because the attacker cannot replay or intercept them the same way they can with a code from an app. If your Microsoft 365 licensing includes Conditional Access, require managed devices for access to email and files so that unmanaged sign-ins are blocked by default.

Finally, make sure you are logging sign-ins, Graph API calls, and file activity, and that someone is actually reviewing those logs. Most small and mid-sized businesses do not have a person watching for this kind of pattern every day. That is where a security operations centre or managed detection service makes the difference between catching this in the first hour and finding out about it weeks later when the attacker is already gone.

Sources

See our security services

Get started today

Have an IT Question?

Our team is ready to help, whether you need advice on cybersecurity, cloud strategy, or AI readiness.