Back to all lessons
Awareness Lessons
last month

Passkey-Themed Phishing Hijacks Cloud Identities and MFA Sessions

Threat actors are exploiting user trust in passkey technology by impersonating IT helpdesk staff and directing victims to phishing sites that harvest both credentials and live session tokens, effectively bypassing MFA protections. Once inside, attackers establish persistent MFA footholds and use Microsoft Graph APIs to silently conduct reconnaissance and exfiltrate data from SharePoint, OneDrive, and email. This attack chain is particularly dangerous because it targets the human element rather than technical vulnerabilities, meaning even well-patched environments remain exposed. The abuse of legitimate cloud APIs like Microsoft Graph for data collection makes detection harder, as malicious activity blends with normal usage patterns. Organizations that rely solely on MFA as a security guarantee without layered detection and user education are especially vulnerable.

Tactical Insight

Immediate actions

  • Train all staff to verify IT helpdesk requests through a known, out-of-band callback number before following any instructions involving credentials or authentication apps.
  • Enforce phishing-resistant MFA methods (e.g., FIDO2 hardware keys) rather than push-notification or OTP-based MFA that can be intercepted via session token theft.
  • Audit and restrict Microsoft Graph API permissions for all registered applications and service principals to least-privilege access.

Detection measures

  • Enable Conditional Access policies that flag or block authentication attempts from proxy/VPN-associated IP ranges and unfamiliar geolocations.
  • Alert on anomalous Microsoft Graph API activity, such as bulk mailbox reads, SharePoint enumeration, or new MFA device registrations outside business hours.
  • Monitor for newly registered MFA devices or authentication app additions and require secondary approval from a manager or security team.

Long-term improvements

  • Implement a Zero Trust architecture that continuously validates user identity, device health, and access context rather than trusting authenticated sessions indefinitely.
  • Establish a formal security awareness program with simulated vishing and phishing exercises specifically targeting helpdesk impersonation scenarios.
  • Deploy session token binding controls and short-lived token lifetimes to limit the window of exploitation if tokens are captured.