Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

Attackers Aren’t Breaking Microsoft Passkeys. They’re Going Around Them.

Attackers are using passkey social engineering to hijack Microsoft 365 identities, exposing a security gap that stronger authentication alone cannot close.

4 Articles

Lean Right

Microsoft alerts to attacks that use passkeys as bait to compromise business accounts, imitating its authentication processes.

·Lisboa, Portugal
Read Full Article

The Microsoft incident shows: A valid login does not protect against data outflow. How attackers use the Graph API and why the NIS2 compliance endangers. Tags: #Compliance #Cyber Security

A recent attack campaign revealed by Microsoft shows how consistently cybercriminal technical security mechanisms can deal with social engineering. They use passkeys, multi-factor authentication, and single sign-on as a pretext for targeted social engineering attacks on corporate accounts and cloud environments. For example, they pretend to be employees of IT support, contact employees via phone or SMS – partly via their private mobile phones [.…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources lean Right
100% Right

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Sapo broke the news in Lisboa, Portugal on Monday, September 21, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal