Summary
Microsoft Security Research has documented an active campaign in which threat actors linked to ShinyHunters, Helix, and related extortion groups use passkey-themed social engineering to push employees into adversary-in-the-middle phishing flows or device-code authentication attacks that bypass multi-factor authentication entirely. The campaign has been active since May 2026 and targets healthcare, education, manufacturing, government, aviation, and professional services organizations in the United States, Canada, and Europe. The passkey is a pretext, not the actual target. Microsoft is the reporting party and the platform being targeted.
Timeline
| Date | Event |
|---|---|
| May 2026 | Microsoft Security Research first observes passkey-themed AiTM phishing campaigns targeting Microsoft 365 corporate accounts |
| May 31, 2026 | Related extortion cluster leak site goes live |
| Sep 10-11, 2026 | Microsoft publishes detailed technical report; attributes activity to clusters linked to ShinyHunters, Helix, and The Com |
What Happened
The attack chain begins with targeted reconnaissance. Attackers research employees and organizational structures from public sources, then contact employees by phone call, SMS, or Microsoft Teams messages, impersonating the target organization's corporate IT help desk. The caller tells the employee they must urgently update a passkey, MFA, or SSO configuration to avoid losing access to corporate systems. The passkey framing creates urgency and exploits employees' awareness that passkey adoption is a real, ongoing IT initiative at many organizations.
Victims directed to phishing sites enter credentials on adversary-in-the-middle pages that relay authentication to Microsoft in real time, capturing credentials and session tokens that allow the attacker to bypass MFA. In device-code authentication variants, victims authorize attacker-controlled access using Microsoft's own legitimate authentication pages. After gaining access, attackers register attacker-controlled MFA methods for persistence, enumerate tenant resources via Microsoft Graph, and systematically download data from SharePoint Online, OneDrive for Business, Exchange Online mailboxes, and Teams chats. Observed phishing infrastructure includes domains such as passkeyhelpdesk.com, secure-passkey.com, and setupmypasskey.com, often with the victim organization's name in a subdomain.
The campaign inverts the expected security posture of passkey adoption. Organizations deploying passkeys to reduce phishing risk may inadvertently create a more convincing social engineering lure for exactly this technique.
Domain Intelligence
microsoft.com — 73.27
Score unchanged from TTO-2026-0907-103. Microsoft is the reporting party in this bulletin — the organization that identified, investigated, and disclosed the campaign targeting its platform. The score reflects microsoft.com's domain trust posture and should not be read as a finding about the threat actors, whose infrastructure uses disposable passkey-themed domains.
The Trust Observatory · thetrustobservatory.com · September 11, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026