Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

“We need to reset your passkey.” How a fake helpdesk takes over Microsoft 365

A call from IT, an urgent passkey setup and a genuine Microsoft page can all be part of one attack. Here is where the trap lies and how to stop it.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
11 September 2026
READING TIME
8 min read
TOPIC
Identity and Access
“We need to reset your passkey.” How a fake helpdesk takes over Microsoft 365

The caller sounds calm and competent. They know the company name, introduce themselves as a member of the helpdesk and say your passkey or single sign-on must be reconfigured before the end of the day. A text with instructions arrives moments later. The screen shows a Microsoft page, so it all resembles a routine task from IT.

Microsoft describes this exact pattern in active cloud intrusions observed since May 2026. The attackers are not breaking passkey technology. They use its name as a convincing pretext and guide a person through a process that grants the criminal access to the account.

The passkey is the lure, not the weak point

The caller creates pressure: a migration is under way, the account may stop working and the ticket must be closed now. They then direct the victim to an adversary-in-the-middle phishing page or ask them to enter a device code on Microsoft’s genuine sign-in site.

The second route is particularly deceptive. The address may be correct, its certificate valid and the sign-in genuinely handled by Microsoft. The problem is the code: it was generated for an application controlled by the attacker. When the user enters it and approves the sign-in, that application receives an access token.

This is why “the page is genuine” does not answer the critical question: who initiated this operation, and for which application?

What happens after a successful sign-in

Microsoft Security Research says attackers added their own authentication method after gaining access, surveyed resources through Microsoft Graph, downloaded files from SharePoint and OneDrive and collected email. One unusual sign-in can therefore develop quickly into persistent access to an organisation’s data.

For a security team, the sequence is more important than any event in isolation:

  1. a sign-in from an unusual location or device;
  2. registration of a new authentication method;
  3. intensive Microsoft Graph queries;
  4. SaaS downloads or mailbox activity.

That chain carries much more meaning than a single alert without context.

What an employee should do during the call

Do not follow instructions during an unsolicited call. End it and contact the helpdesk through a number in the corporate directory, messaging platform or support portal. Do not call the number in your recent-call list or use a link supplied by the caller.

Never enter a device code you did not initiate on your work device. Read the application name, permission scope and every prompt. Urgency, a threat that the account will be disabled and a request to bypass the normal ticket process should end the call, not accelerate the click.

If you have already approved the code, report the incident immediately. Changing the password alone may not be enough because the attacker may hold a live session or token, or may have registered another sign-in method.

What IT should put in place

Microsoft recommends phishing-resistant MFA enforced through Conditional Access, tight control over security-information registration, managed-device requirements and blocking the device-code flow when there is no explicit business need for it. Organisations should also review applications and permissions, enable Microsoft Graph activity logs and audit mailboxes.

After a confirmed incident, responders should revoke sessions and tokens, reset credentials, remove attacker-added authentication methods and mailbox rules, and then carry out a secure re-registration.

The helpdesk procedure needs to be as concrete as the technical configuration. Employees should know whether IT ever conducts setup by telephone, how to verify a support agent and where to report a suspicious conversation.

What the source says and what Breachroad concludes

On 9 September 2026, Microsoft described social engineering that uses passkeys as its theme. Details about supposed helpdesk calls and texts, AiTM phishing, device codes and subsequent Microsoft 365 activity come from Microsoft Security Research’s observations.

Breachroad’s conclusion is that training cannot stop at spotting fake domains. Users must also know how to question a genuine sign-in page when somebody else is controlling the process. Passkey technology remains a strong control; the problem is persuading a person to authorise somebody else’s operation.

For the underlying concept, read how passkeys move us beyond passwords. We help organisations rehearse verification in realistic situations through cybersecurity training.

SHARE / COPY