TTO-2026-0911-117 · September 11, 2026 PhishingActive Campaign

Passkey Lures Used to Push Microsoft 365 Users Into MFA-Bypassing AiTM Phishing Since May 2026

microsoft.comAiTM phishingShinyHunters and Helix linkedPasskey lure as social engineering pretextActive since May 2026Microsoft 365 SharePoint OneDrive Exchange

Summary

Microsoft Security Research has documented an active campaign in which threat actors linked to ShinyHunters, Helix, and related extortion groups use passkey-themed social engineering to push employees into adversary-in-the-middle phishing flows or device-code authentication attacks that bypass multi-factor authentication entirely. The campaign has been active since May 2026 and targets healthcare, education, manufacturing, government, aviation, and professional services organizations in the United States, Canada, and Europe. The passkey is a pretext, not the actual target. Microsoft is the reporting party and the platform being targeted.

Timeline

DateEvent
May 2026Microsoft Security Research first observes passkey-themed AiTM phishing campaigns targeting Microsoft 365 corporate accounts
May 31, 2026Related extortion cluster leak site goes live
Sep 10-11, 2026Microsoft publishes detailed technical report; attributes activity to clusters linked to ShinyHunters, Helix, and The Com

What Happened

The attack chain begins with targeted reconnaissance. Attackers research employees and organizational structures from public sources, then contact employees by phone call, SMS, or Microsoft Teams messages, impersonating the target organization's corporate IT help desk. The caller tells the employee they must urgently update a passkey, MFA, or SSO configuration to avoid losing access to corporate systems. The passkey framing creates urgency and exploits employees' awareness that passkey adoption is a real, ongoing IT initiative at many organizations.

Victims directed to phishing sites enter credentials on adversary-in-the-middle pages that relay authentication to Microsoft in real time, capturing credentials and session tokens that allow the attacker to bypass MFA. In device-code authentication variants, victims authorize attacker-controlled access using Microsoft's own legitimate authentication pages. After gaining access, attackers register attacker-controlled MFA methods for persistence, enumerate tenant resources via Microsoft Graph, and systematically download data from SharePoint Online, OneDrive for Business, Exchange Online mailboxes, and Teams chats. Observed phishing infrastructure includes domains such as passkeyhelpdesk.com, secure-passkey.com, and setupmypasskey.com, often with the victim organization's name in a subdomain.

The campaign inverts the expected security posture of passkey adoption. Organizations deploying passkeys to reduce phishing risk may inadvertently create a more convincing social engineering lure for exactly this technique.

Domain Intelligence

microsoft.com — 73.27

Score unchanged from TTO-2026-0907-103. Microsoft is the reporting party in this bulletin — the organization that identified, investigated, and disclosed the campaign targeting its platform. The score reflects microsoft.com's domain trust posture and should not be read as a finding about the threat actors, whose infrastructure uses disposable passkey-themed domains.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 11, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026