# Fake Passkey Prompts Used to Hijack Microsoft Cloud Accounts and Steal Data

*Sunday, September 13, 2026 at 12:06 PM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-13T12:06:45.285Z (1h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/17707.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers are taking over Microsoft cloud accounts by luring users into bogus passkey “updates,” then adding their own multi‑factor authentication methods and pulling data from SharePoint, OneDrive and email, security researchers warn.

A new phishing technique is turning a security feature into an attack route against Microsoft cloud users.

According to technical reporting on 13 September, threat actors are sending people to pages that pose as legitimate Microsoft or browser interfaces and tell them they must install or update a passkey. Passkeys are cryptographic credentials meant to replace passwords.

When targets follow the bogus instructions, attackers gain the access they need to add their own multi‑factor authentication (MFA) methods to the account. Once that’s done, they can keep logging in even if the original user changes their password.

From inside the account, the intruders quietly browse and extract data from services such as SharePoint, OneDrive and mailboxes. They can also use the compromised identity to send further phishing messages deeper into an organisation.

The pattern shows how identity systems designed to reduce risk can be reversed if users can’t distinguish a real security prompt from a fake one delivered through a malicious web page.

Key things to track now are how Microsoft and other providers change their MFA‑enrolment protections, and whether other incident reports start pointing to similar fake passkey flows as a growing cause of cloud account takeovers.
