← Back to blog

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Passkeys were supposed to make logging into our accounts completely secure by replacing easy-to-guess passwords with cryptographic keys stored on our phones or computers. Unfortunately, cybercriminals have found a clever way around this by using AitM or adversary-in-the-middle phishing techniques. In these attacks, hackers trick you into entering your passkey on a convincing fake login page that sits between you and a service like Microsoft 365, capturing your secure session token in real time and gaining full access to your cloud accounts and private data without ever needing your actual password.

Because these phishing sites look nearly identical to the real login portals you use every day, it is becoming increasingly difficult for everyday internet users to spot the difference on their own. Attackers can quickly bypass multi-factor authentication and dig through your corporate emails, documents, and sensitive communications before you even realize anything is wrong. Vigilance is your first line of defense, but you do not have to navigate these advanced threats completely alone. If you ever receive an unexpected login prompt or an email that feels just a little bit off, you can forward it to scan@report.mailforensis.com to get a clear, plain-English threat analysis in seconds and keep your digital life safe.

Got a suspicious email?

Forward it to scan@report.mailforensis.com and get a clear answer in seconds — free.

Try MailForensis free →