Skip to main content
by IT Integrations Team

Passkey Phishing and Fake IT Help Desk Calls Are Hijacking Microsoft 365 Accounts

On September 9 and 10, Microsoft published details of a campaign that should make every business owner using Microsoft 365 sit up. Attackers are calling and texting employees, pretending to be from the company's own IT help desk, and telling them their passkey or multi-factor authentication needs to be updated right now. The employee follows the link, does what the "help desk" says, and hands over their account without ever typing a password into the real Microsoft login page.

The uncomfortable part is what they are targeting. For two years the advice from every IT company, including ours, has been the same: turn on MFA, move to passkeys, stop relying on passwords. That advice is still correct. But the attackers have read the same playbook, and they have figured out that the fastest way past a passkey is not to break it. It is to call a person and talk them through disabling it themselves.

This post breaks down how the attack works, why "we already have MFA" does not close the door, and the specific Microsoft 365 settings and habits that actually stop it. Written for Fort Worth business owners, not for security engineers.

What Microsoft actually reported

The fake help desk call

Microsoft has been tracking this activity since May 2026. The attack almost always starts the same way. Someone calls or texts an employee's personal cell phone, says they are from the company's IT department, and creates a small, believable problem: your passkey is expiring, your single sign-on needs to be re-enrolled, your account will lose access if you do not act. Then they send an SMS with a link to a website that looks exactly like the Microsoft sign-in screen.

The caller is not guessing. Microsoft noted the operators invest heavily in research before they dial, pulling employee names, roles, and reporting structure from public sources like LinkedIn. So the call does not sound like a robocall. It sounds like someone who knows your company, using your manager's name, calling about a system you actually use.

This is the same voice-phishing pattern we wrote about earlier this year in our piece on help desk vishing calls targeting Fort Worth businesses. The target has shifted from password resets to passkeys and MFA, but the human trick is identical. If you want the broader picture on how these social engineering attacks fit into a real security program, our cybersecurity services page walks through the layers that matter.

Why "we have MFA" is not the end of the story

Here is the technical reality, in plain terms. Once the employee is on the fake login page, the attacker uses one of two methods. The first is adversary-in-the-middle, where the fake page quietly passes everything the employee types through to the real Microsoft, including the MFA approval, and steals the resulting session. The second is device code phishing, where the employee is tricked into approving a login that is actually happening on the attacker's computer.

In one case Microsoft investigated, the attackers took over an account through a device code trick without stealing a single credential or cookie. MFA was on the whole time. It did not matter, because the person approved the login themselves.

Then comes the part that turns a bad afternoon into a breach. The attacker registers their own MFA method on the account, usually a new phone number or authenticator app. Now they can log back in whenever they want, without the employee involved at all. Microsoft described the goal directly: turn a temporary compromise into a persistent foothold. From there they use the Microsoft Graph interface to inventory the whole tenant, then download files from SharePoint and OneDrive and pull email out of Exchange Online, sometimes over several days.

None of this requires malware on a laptop. It all happens in the cloud, through legitimate Microsoft interfaces, which is exactly why it is hard to spot.

What Fort Worth businesses should actually do

The Microsoft 365 settings most businesses never turned on

The good news is that Microsoft 365 already has the controls to blunt this attack. Most businesses just never turned them on, because the account was set up years ago and nobody has revisited the security configuration since.

The short list we check first: Conditional Access policies that block sign-ins from unmanaged devices and unexpected locations, restrictions on the device code authentication flow (most small businesses never use it and can turn it off entirely), phishing-resistant MFA set as the requirement rather than an option, and alerting that fires the moment a new MFA method is registered on any account. That last one is the tripwire for this specific attack. If someone adds a phone number to an executive's account at 2 a.m., someone on your side should know within minutes.

We also look hard at admin accounts. Microsoft's report showed attackers hunting for high-privilege identities once they get in. If half your staff has global admin rights, a single stolen account becomes a full tenant compromise. Getting the Microsoft 365 configuration right is a core part of the Microsoft 365 management work we do for clients, and it is usually the highest-value hour we spend in a new environment.

Train people for the exact script

Technology alone will not fix a problem that starts with a phone call. Your team needs to know the specific script before it happens: no legitimate IT help desk, including ours, will ever call your personal cell and walk you through changing your passkey or MFA on a link they text you. If that call comes in, the correct response is to hang up and call your IT provider back on the number you already have.

That is a five-minute conversation at a staff meeting, and it is worth more than most of the security awareness training people click through and forget. When the local team that answers your calls is a known quantity, a stranger claiming to be "IT" is easier to catch. That is part of why we push the managed IT model where you actually know who picks up the phone. Familiarity is a security control.


Worried your Microsoft 365 accounts are exposed to this? IT Integrations reviews Microsoft 365 security configurations for Fort Worth businesses and the surrounding DFW area. Call us at (817) 808-1816 or contact us for a free IT assessment.


The Fort Worth angle

This campaign lands especially hard on the kinds of businesses we work with around Fort Worth. The attack targets personal cell phones, and a lot of local companies run on personal phones. Home health and hospice agencies have clinicians in the field all day, checking schedules and messages from their own devices between patient visits. Construction crews from Weatherford to Burleson live on their phones at the jobsite. When the work already happens on a personal device, a text claiming to be from IT does not look out of place.

Healthcare practices have a second problem stacked on top. If an attacker gets into a Microsoft 365 account and starts pulling files out of SharePoint and email out of Exchange, and that data includes patient information, you are not just dealing with a security incident. You are dealing with a HIPAA breach, with the notification obligations and the Office for Civil Rights attention that come with it. We cover why identity is now the front line of healthcare compliance in our HIPAA compliance work, and this attack is a textbook example of how a single hijacked login turns into a reportable event.

Professional services firms have their own version of the risk. A hijacked account at a law office or accounting practice is not just an IT headache, it is client confidentiality out the door, and the kind of thing that ends up in an awkward conversation with the people who trust you with their information. Water utility districts and the smaller special districts around the metro sit in a similar spot, running lean on staff while holding data and access that matters more than their headcount suggests.

For businesses out in Weatherford and the western DFW communities we serve, the practical takeaway is the same one it always is: the size of your company does not decide whether you are a target. Your Microsoft 365 tenant is worth the same to an attacker whether you have six employees or six hundred. The attackers are not picking targets by revenue. They are picking them by whichever account answers the phone and clicks the link.

What we see when we audit a new client's Microsoft 365 environment

We take over a lot of Microsoft 365 environments from previous providers, and the same gaps show up almost every time. This is not a knock on anyone. Most of these tenants were configured correctly for 2019 and simply never updated as the threats changed.

The device code authentication flow is almost always still enabled, even though the business has never once needed it. Conditional Access is frequently either off or set up loosely enough that a login from a brand-new device in another state sails right through. Nobody is watching for new MFA methods being registered, so the exact persistence trick in Microsoft's report would go unnoticed until the data was already gone. And admin rights tend to have spread over the years, so more accounts than anyone realizes could hand over the keys to the whole tenant.

The reason this matters is that the attack Microsoft described does not trip traditional alarms. There is no virus for antivirus to catch. Each individual action, one file download, one login, one settings change, looks normal on its own. Microsoft made this point plainly: the abuse rarely looks suspicious in a single event, and you only catch it by looking at the pattern across events. That kind of monitoring is not something that comes turned on out of the box. It has to be built into how the environment is managed, which is the whole argument for having someone actively watching the tenant rather than only showing up when something breaks.

Industry data backs up why the human-driven version of this matters so much. According to Verizon's 2026 Data Breach Investigations Report, the human element was present in 62 percent of breaches, and the report specifically calls out mobile social engineering success climbing sharply. This attack is that statistic in action: a text to a personal phone, a convincing voice on the line, and a person doing what they were asked.

What to do if you think an account was already compromised

If any of this made you wonder about a call one of your people got last month, do not wait to be sure before you act. The whole design of this attack is to stay quiet, so the honest answer is that most businesses will never be completely certain nothing happened. Better to run the checklist and find nothing than to assume the best.

Move fast on the account itself

The first job is to cut off access and kick out any session the attacker is still holding. That means resetting the user's password, revoking their active sign-in sessions so a stolen session token stops working, and then reviewing every MFA method registered on the account and removing anything the user does not recognize. That last step is the one people forget, and it is the one that matters most, because the attacker's whole plan was to leave their own MFA method behind. If you reset the password but leave their authenticator in place, you have not actually locked them out.

Then look at what they could reach

Once the account is secured, the question becomes what the account could see while it was open. That means checking the Microsoft 365 audit logs for file downloads, email access, and any changes to mailbox rules, since attackers often set up forwarding rules to keep reading mail after they lose access. It also means looking at whether the compromised account had admin rights or access to anything sensitive, and for healthcare practices, whether any of the data touched was protected health information. This is exactly the kind of work our help desk and managed IT team handles when a client calls in worried, and it is a lot less stressful when someone already knows your environment before the bad day arrives.

If you do not have a written plan for these first hours, that gap is worth closing on a calm afternoon rather than discovering it during an incident. A basic account-compromise response plan is a normal part of the IT strategy work we do with clients, and it does not require a big budget to put in place.

Frequently Asked Questions

If we already use passkeys and MFA, are we protected from this?

You are better protected than a business relying on passwords alone, and you should absolutely keep them on. But this campaign specifically works around MFA by getting the employee to approve the login themselves, or by adding the attacker's own MFA method after they get in. The fix is not more MFA prompts. It is phishing-resistant MFA set as a hard requirement, Conditional Access that limits where and how people can sign in, and alerting when authentication methods change. It is also training people to recognize the fake help desk call, because that is the door the whole attack walks through.

How would we even know if this happened to us?

Honestly, most small businesses would not know until data started showing up somewhere it should not, or a client asked why they got a strange email. The signs are in the Microsoft 365 audit logs: a new MFA method registered on an account, a sign-in from an unfamiliar device or location, unusually high file download activity in SharePoint or OneDrive. Those logs exist in your tenant right now, but someone has to be watching them and know what normal looks like for your business. If nobody is, the answer to "how would we know" is usually "we would not, in time."

What is the single most important thing to do this week?

Tell your team, out loud, that IT will never call their personal phone and walk them through changing their passkey or MFA on a texted link, and that the right move is to hang up and call the known IT number back. That one conversation costs nothing and closes the most common entry point. After that, the highest-value technical step is turning off the device code authentication flow if your business does not use it, and turning on alerts for new MFA method registration.

We are a healthcare practice. Does this change our compliance exposure?

Yes. If a hijacked Microsoft 365 account is used to access or download files containing protected health information, that is a reportable HIPAA breach, not just an IT problem. This is why we treat Microsoft 365 identity security as part of compliance, not separate from it. A strong security risk assessment should already account for cloud account takeover as a threat, and if yours has not been updated to reflect how these attacks actually work now, that is a gap worth closing.

Can you check our environment without us switching providers first?

Yes. We do Microsoft 365 security reviews for Fort Worth businesses whether or not they are clients, and there is no obligation attached to it. We look at your Conditional Access, authentication methods, admin roles, and logging, and we tell you what we find in plain language. If you like what you see and want us to manage it, great. If not, you keep the report and hand it to whoever does.

Next Steps

The passkey phishing campaign Microsoft disclosed is not a reason to panic, and it is not a reason to abandon MFA. It is a reminder that security is not a switch you flip once. The attackers adapt, and the settings that were fine three years ago need another look. The businesses that come through this fine are the ones that had Conditional Access configured, the device code flow shut off, alerting on account changes, and a team that knows what a fake IT call sounds like.

If you are not sure where your Microsoft 365 environment stands on any of that, it is worth an hour to find out before someone else finds out for you.

Ready to see where your Microsoft 365 accounts actually stand? IT Integrations provides Microsoft 365 security, managed IT, and cybersecurity services for Fort Worth businesses and the surrounding DFW metro. Call (817) 808-1816 or schedule a free IT consultation today.

Sources: Microsoft Security Blog, Passkey-themed social engineering leads to identity and cloud compromise (September 9, 2026); The Hacker News, Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data (September 13, 2026); Verizon 2026 Data Breach Investigations Report.

Need Help With Your IT?

IT Integrations provides managed IT services, cybersecurity, and compliance support for Fort Worth businesses. Let's talk about what you need.

Call Us Get a Quote