Fake IT helpdesk calls are opening the door to Microsoft 365 accounts

Microsoft says attackers are ringing staff on personal phones, walking them through passkey 'updates', then pulling SharePoint and OneDrive files.

ThreatVectr Newsdesk· Editor: Lee Brown· 4 min read
Full-frame edge-to-edge photoreal editorial shot of a smartphone lying face-up on a dark office desk, screen showing a generic unknown-caller interface glowing
Share

Key points

  • Microsoft has been tracking a wave of cloud break-ins since May 2026 that start with a phone call to an employee's personal mobile pretending to be the IT helpdesk.
  • The callers push a passkey or single sign-on 'update' that actually hands over the victim's Microsoft 365 session, letting attackers skip the login prompt entirely.
  • Once inside, intruders use Microsoft Graph, a programming interface for reading mailboxes and files, to pull data from SharePoint, OneDrive and Exchange APIs, often within an hour.
  • Attackers register lookalike domains such as companyname.secure-passkey[.]com through the Nicenic registrar, spinning them up in hours.
  • The techniques overlap with tradecraft associated with ShinyHunters and related extortion crews, a group Threat Vectr has covered 25 times since first reporting on them on 28 May 2026.

Microsoft is warning that attackers have found a reliable way into corporate Microsoft 365 accounts, and it doesn't involve breaking any software. It involves a phone call.

In an advisory published by the Microsoft Security Response Center, the company says its researchers have been tracking cloud intrusions since May 2026 in which staff get an unexpected call or text on their personal mobile from someone claiming to be internal IT. The caller says a passkey, a passwordless login tied to a device, needs urgent reconfiguration or the employee will lose access. A link follows. The page looks convincingly like a normal Microsoft sign-in screen. It isn't.

How does the attack actually work?

The fake page sits in the middle of the login. When the victim types their password and approves the multi-factor prompt on their phone, the attacker's server quietly copies the resulting session token, the digital pass that tells Microsoft the user is already logged in. From that point the attacker is signed in as the employee, with no further password or code required.

Microsoft calls this an adversary-in-the-middle attack. In some cases the criminals use a variant called device code phishing, where the victim is talked into typing a short code into a real Microsoft page, unwittingly authorising the attacker's own device. The passkey narrative is a pretext; the session token is the prize.

As we reported on 4 September 2026, passkeys aren't the bulletproof fix they're often sold as: researchers had already catalogued 39 ways to work around them without touching the underlying cryptography.

What do the attackers do once they are in?

They move fast. Microsoft's investigators watched sessions lasting around an hour, during which intruders added their own authentication method to the account for later re-entry, then used Microsoft Graph to list and download files from SharePoint and OneDrive and collect mail through Exchange APIs.

Much of this is automated. One operation ran on custom Node.js code driving the Graph interface, letting attackers enumerate a tenant's files at machine speed rather than clicking through folders.

Because the phishing link is often opened on a personal phone that isn't monitored by corporate security tools, the first sign anything happened is often just the employee remembering the call.

Who is behind it?

Microsoft doesn't name a group in this advisory. The techniques overlap with tradecraft associated with ShinyHunters and related extortion crews that have hit cloud tenants heavily through 2025 and into 2026. Helpdesk impersonation, passkey lures and throwaway domains registered through Nicenic are all consistent with that cluster.

What should ordinary staff do?

Treat any unexpected call about passkey or MFA configuration as suspicious, even if the caller knows your name and role. Hang up and ring your own IT team on a number you already have. Never type a code from a phone call into a login page, and never approve an MFA prompt you didn't trigger yourself.

My read: the interesting shift here isn't the phishing kit, it's the phone. Attackers have worked out that the personal mobile is the softest surface a company has, because nothing corporate sees what happens on it. Expect more of this, not less.

© 2026 Threat Vectr