[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fUb5dwumQyqqIupFDq3389TA9dalXazwNcMWQOYZAzmc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":26,"created_at":27,"published_at":28,"article":29,"tags":33,"podcasts":46},"4a78394a-cbb5-4970-be52-e00f1fe3b159","passkey-phishing-campaigns-harvest-microsoft-365-credentials-and-session-tokens","ac0b574c-a787-47f0-8df2-ba72fee57ebe","Passkey-Phishing Campaigns Harvest Microsoft 365 Credentials and Session Tokens","Threat actors are exploiting user trust in passkeys and SSO by impersonating IT help desks and luring victims to adversary-in-the-middle (AiTM) phishing sites that steal both credentials and authenticated session tokens — effectively bypassing MFA entirely. The root problem is that employees lack the awareness to distinguish legitimate IT communications from sophisticated social engineering, and organizations often fail to enforce phishing-resistant authentication methods that cannot be intercepted mid-session. Session token theft is particularly dangerous because it grants attackers persistent access without needing passwords or MFA codes. This matters because groups like ShinyHunters have demonstrated they can monetize stolen Microsoft 365 access at scale, leading to data exfiltration, ransomware staging, and supply chain attacks on downstream customers and partners.","**Immediate Actions:**\n- Deploy phishing-resistant MFA (FIDO2 hardware keys or platform passkeys) that cryptographically bind authentication to the legitimate origin domain, neutralizing AiTM attacks.\n- Enforce Conditional Access policies in Microsoft 365 that restrict logins to compliant, managed devices and flag anomalous session token reuse.\n- Alert employees via a targeted security bulletin about the active passkey\u002FSSO-themed IT help desk impersonation campaign.\n\n**Long-Term Improvements:**\n- Establish a verified, out-of-band IT help desk contact channel (e.g., a pinned intranet page) so employees always confirm support requests through a trusted source.\n- Implement continuous token-lifetime management and short-lived session tokens to limit the window of exploitation after a session is compromised.\n- Conduct regular phishing simulation exercises specifically themed around SSO, passkeys, and IT impersonation scenarios to build employee muscle memory.\n\n**Detection & Response Measures:**\n- Enable Microsoft Entra ID sign-in risk policies and monitor for impossible travel, unfamiliar device sign-ins, and suspicious OAuth token grants.\n- Ingest Microsoft 365 audit logs into a SIEM and create alerts for bulk email access, mass file downloads, or forwarding rule creation following any new authentication event.\n- Maintain a pre-approved incident response playbook for AiTM credential compromise that includes immediate token revocation and tenant-wide sign-out.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25],"CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 6: Access Control Management","CIS Control 14: Security Awareness and Skills Training","CIS Control 17: Incident Response Management","NIST SP 800-63B: Digital Identity Guidelines — Phishing-Resistant AAL3 Authenticators","NIST AC-2: Account Management","NIST AC-17: Remote Access","NIST SI-3: Malicious Code Protection","NIST IR-4: Incident Handling","MITRE ATT&CK T1111: MFA Interception","MITRE ATT&CK T1539: Steal Web Session Cookie","MITRE ATT&CK T1566.002: Spearphishing Link","GDPR Article 32: Security of Processing (for EU data involved in breaches)","Microsoft Zero Trust Principle: Verify Explicitly — Enforce device compliance and sign-in risk evaluation","published","2026-09-11T18:20:23.619577+00:00","2026-09-11T18:20:23.292+00:00",{"id":7,"url":30,"slug":31,"title":32},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fpasskey-themed-phishing-attacks-lead-to-microsoft-365-data-theft\u002F","passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft-82dfd2","Passkey-themed phishing attacks lead to Microsoft 365 data theft",[34,40],{"id":35,"name":36,"slug":37,"description":38,"color":39},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":41,"name":42,"slug":43,"description":44,"color":45},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]