Your Passkey Wont Save You from the Next Wave of Identity Theft
Think passkeys are unhackable? Think again. New research shows how attackers are using clever social engineering to turn your strongest security tools against you.

Key takeaways
- Passkeys are highly secure but can still be subverted through social engineering and malicious enrollment flows.
- Attackers are using vishing (voice phishing) to impersonate IT support and guide users into authorizing attacker-controlled tokens.
- Identity security must move beyond just monitoring logins to observing the entire identity lifecycle and subsequent cloud data activity.
- Bulk data theft from platforms like SharePoint and OneDrive is the primary goal following a successful identity compromise.
The Great Identity Paradox
Imagine building a digital fortress with walls so thick that no battering ram could ever hope to breach them. You install a passkey system, widely considered the gold standard of modern authentication, believing your data is finally untouchable. Then, the phone rings. A helpful voice from IT support guides you through a quick security update. Within minutes, that unhackable fortress has been emptied from the inside out. This is not a hypothetical scenario; it is the reality of a sophisticated new wave of social engineering attacks targeting Microsoft cloud environments.
For years, the cybersecurity industry has touted passkeys as the silver bullet to end phishing. By replacing passwords with cryptographic keys stored on devices, we theoretically removed the human element from the vulnerability equation. However, as a security blog published by Microsoft on September 9, 2026, reveals, attackers have simply shifted their focus. Instead of stealing a password, they are now social engineering the very process of identity enrollment and token issuance.
The Vishing Loop: How Modern Identity Theft Works
The attack sequence typically begins with a phone call, a technique known as vishing (voice phishing). According to reporting by Help Net Security, these attackers impersonate corporate IT support or a security desk. They build rapport with the victim, often citing a technical glitch or a mandatory security upgrade to explain why the user needs to perform certain actions on their account. The goal is to manipulate the victim into enrolling a new authentication method or authorizing a session that the attacker controls.
Once the attacker gains a foothold, the speed of the breach is breathtaking. Microsoft researchers observed that defenders must now treat identity signals and cloud-workload signals as one connected sequence. The attacker does not just stop at a successful sign-in; they immediately pivot to Graph reconnaissance to map the organization, followed by the issuance of long-lived tokens. The ultimate objective is almost always the same: the bulk exfiltration of sensitive data from SaaS platforms like SharePoint, OneDrive, and Exchange.
What Changed: The Evolution of the Attack
Previously, social engineering was largely about tricking a user into typing their credentials into a fake website. The industry responded with Multi-Factor Authentication (MFA) and eventually passkeys. What is new here is the tactical shift toward manipulating the identity lifecycle itself. Attackers are no longer just looking for a key; they are convincing users to create a new key for them or to validate an attacker-authorized session through a spoofed authentication page.
This represents a significant delta in threat actor behavior. By moving upstream in the authentication process, hackers can bypass the inherent security of FIDO2 and other modern standards. The breach does not happen because the technology failed; it happens because the human trust in the enrollment process was exploited. This highlights a critical lesson for the industry: technology can be perfect, but the workflows surrounding it are often remarkably fragile.
Why It Matters
This development is particularly alarming because it erodes confidence in the very tools designed to protect us. If users feel that even passkeys are not safe, they may become less willing to adopt modern security measures. For organizations, the impact is even more severe. These attacks are not just about compromising a single user account; they are about gaining persistent access to the entire cloud workload. Once an attacker has authorized their own tokens, they can bypass many traditional perimeter defenses, moving laterally through cloud storage and email systems to steal intellectual property or corporate secrets.
The Broader Threat Landscape
While identity attacks are evolving, traditional software vulnerabilities remain a primary threat vector. This was reinforced recently when CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. According to a report from The Hacker News, these flaws affect critical infrastructure tools like JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. The ScreenConnect flaw, for instance, allows for unauthorized file transfer and execution, providing another path for attackers to gain a foothold in sensitive environments. These two trends (socially engineered identity theft and rapid exploitation of infrastructure flaws) are converging to create a high-pressure environment for security teams.
What to Watch Next
Looking ahead, we should expect to see the integration of generative AI into these vishing attacks. Imagine a scenario where the voice of the IT technician on the phone is not just a convincing actor, but a deepfake clone of a victim's actual manager or a known colleague. This will make the initial social engineering phase even more difficult to detect. Furthermore, as organizations move toward autonomous agents (a trend recently discussed by Anthropic CEO Dario Amodei), the surface area for these attacks will expand. Amodei warned that frontier AI systems could soon coordinate swarms of agents capable of overwhelming internet-scale systems, suggesting that our current defensive strategies may soon be outdated.
Practical Steps for Protection
To defend against these sophisticated identity attacks, organizations and individuals should take the following steps:
- Verify Identity Out-of-Band: If you receive a call from IT support asking you to change security settings or enroll a new device, hang up and call them back through a known, official company number.
- Monitor Identity Lifecycle Events: Security teams should move beyond monitoring successful logins and start looking for unusual patterns in authentication-method enrollment and session token issuance.
- Implement Strict Token Policies: Use conditional access policies to limit the lifespan of session tokens and require re-authentication for access to highly sensitive data like SharePoint and OneDrive.
- Educate on Modern Phishing: Training programs must evolve to teach users that passkeys and MFA are not magic shields. Users need to understand that the process of setting up these tools is itself a target for hackers.
The digital landscape is shifting under our feet. While we have built better locks, the thieves have simply learned how to talk their way through the front door. By staying vigilant and understanding the connected nature of identity and cloud security, we can begin to close the gap between technological capability and human vulnerability.
Sources (7)
Discussion (0)
Commenting as
No comments yet. Be the first to share your thoughts!
The discussion could not be loaded. Please refresh the page.
Cybersecurity and privacy journalist


