Illustration of passkey phishing attacks targeting Microsoft 365 corporate accounts

Passkey Phishing Attacks: Critical Microsoft 365 Alert 2026

Passkey Phishing Attacks: What Australian Businesses Must Know in 2026

Passkey phishing attacks have emerged as a critical threat to Australian organisations, with Microsoft confirming that notorious cybercriminal groups are exploiting the trust placed in modern authentication methods to steal corporate data. This sophisticated campaign, linked to ShinyHunters, Helix, and other extortion gangs, specifically targets Microsoft 365 environments through deceptive passkey and single sign-on (SSO) themed social engineering tactics.

The irony is stark: passkeys were designed to eliminate phishing risks, yet threat actors have weaponised the technology’s reputation for security to trick users into surrendering their credentials. For Australian businesses relying on Microsoft 365 for daily operations, understanding this attack vector is no longer optional—it’s essential for survival.

“Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.”

BleepingComputer

How Do Passkey Phishing Attacks Work?

Unlike traditional phishing that requests passwords directly, these attacks exploit user confidence in newer authentication technologies. Attackers send convincing emails or messages claiming the recipient needs to register a new passkey or update their SSO configuration to maintain account access.

The attack chain typically follows this pattern:

  1. Initial contact via email impersonating Microsoft or IT administrators
  2. Urgency creation through warnings about account suspension or security requirements
  3. Credential harvesting via fake passkey registration portals that capture existing authentication tokens
  4. Account takeover and subsequent data exfiltration from Microsoft 365 services

Why Traditional Security Controls Fail

These passkey phishing attacks succeed because they bypass the cognitive defences users have developed against conventional phishing. Employees trained to scrutinise password requests may lower their guard when asked to “enhance security” through passkey enrolment.

The attackers also leverage adversary-in-the-middle (AiTM) techniques, intercepting authentication tokens in real-time. This means even accounts protected by multi-factor authentication (MFA) can be compromised during the attack window.

Which Threat Groups Are Behind These Attacks?

Microsoft’s threat intelligence has linked this campaign to several prominent cybercriminal organisations:

  • ShinyHunters — notorious for large-scale data breaches affecting millions of users globally
  • Helix — an emerging extortion group specialising in corporate data theft
  • Associated extortion gangs — leveraging stolen data for ransom demands and dark web sales

These groups have historically targeted organisations across healthcare, finance, technology, and professional services—sectors well-represented in the Australian economy. Their sophistication and resources make them formidable adversaries for businesses of any size.

Business Impact of Microsoft 365 Data Theft

The consequences of a successful passkey phishing attack extend far beyond the initial breach. Australian organisations face significant risks across multiple dimensions:

Financial Consequences

  • Direct extortion demands averaging $500,000 to $2 million AUD for enterprise targets
  • Regulatory fines under the Privacy Act and potential OAIC investigations
  • Business interruption costs during incident response and recovery
  • Legal expenses from potential class action litigation

Operational Disruption

With Microsoft 365 serving as the productivity backbone for most organisations, compromised accounts can lead to email system lockouts, SharePoint data loss, and Teams communication breakdowns. Recovery timelines often span weeks, not days.

Reputational Damage

Data breaches involving customer information trigger mandatory notification requirements under Australian law. The resulting publicity can erode client trust and competitive positioning for years following an incident.

How to Protect Your Organisation from Passkey Phishing

Defending against these sophisticated attacks requires a multi-layered approach combining technical controls, user awareness, and proactive monitoring. Consider implementing these protective measures immediately:

Technical Controls

  • Deploy phishing-resistant MFA — hardware security keys remain the gold standard
  • Enable conditional access policies — restrict authentication to compliant devices and trusted locations
  • Implement token binding — prevent session hijacking through adversary-in-the-middle attacks
  • Configure Microsoft 365 alert policies — monitor for suspicious sign-in patterns and impossible travel

User Awareness Training

Your workforce needs specific education about passkey phishing attacks. Generic security awareness training is insufficient—employees must understand that attackers now exploit security technologies themselves as social engineering lures.

If your organisation lacks internal resources for comprehensive security training, consider engaging our security awareness training services to build a human firewall against these threats.

Incident Response Preparation

Ensure your incident response plan specifically addresses Microsoft 365 compromise scenarios. Time is critical when attackers have access to cloud email and collaboration platforms—pre-established playbooks dramatically reduce response times.

Frequently Asked Questions

What is a passkey phishing attack?

A passkey phishing attack is a social engineering technique where cybercriminals send fraudulent communications claiming recipients need to register or update passkeys for their accounts. Rather than targeting passwords directly, these attacks exploit trust in modern authentication methods to harvest credentials or session tokens, ultimately leading to account compromise and data theft.

Can passkeys be phished if they’re supposed to be phishing-resistant?

Legitimate passkeys themselves cannot be phished—they use cryptographic verification tied to specific websites. However, attackers exploit the concept of passkeys as a social engineering lure, tricking users into visiting fake portals that capture existing credentials or authentication tokens before passkey registration completes. The attack targets human behaviour, not the passkey technology itself.

How can I tell if my Microsoft 365 account has been compromised?

Warning signs include unexpected password reset notifications, unfamiliar devices in your sign-in history, emails sent from your account that you didn’t write, missing or modified files in OneDrive/SharePoint, and inbox rules you didn’t create. Microsoft 365 administrators should regularly review sign-in logs and enable alerts for anomalous activity.

Key Takeaways for Australian Businesses

  • Passkey phishing attacks represent a new evolution in social engineering targeting Microsoft 365
  • Threat groups including ShinyHunters and Helix are actively exploiting this technique
  • Traditional MFA can be bypassed through adversary-in-the-middle token theft
  • Hardware security keys provide the strongest protection against these attacks
  • Employee training must specifically address passkey and SSO-themed phishing lures
  • Incident response plans need updating to address cloud identity compromise scenarios

Secure Your Microsoft 365 Environment Today

Passkey phishing attacks demonstrate that cybercriminals continuously adapt their techniques to exploit emerging technologies and user trust. Australian organisations must respond with equally dynamic defences—combining robust technical controls, targeted user education, and rapid incident response capabilities.

Don’t wait until your organisation becomes the next victim of data theft and extortion. Speak with our security team to assess your Microsoft 365 security posture and implement defences against these sophisticated threats. Our vulnerability management services can identify gaps in your authentication security before attackers exploit them.

The threat landscape has evolved—your security strategy must evolve with it.

Tagged , , , , , .