Hackers Pose as IT Support, Use Fake Passkey Lures to Steal Microsoft 365 Access
Medium · Hackread ·
What happened
Microsoft warns attackers impersonate IT support and use fake passkey lures to steal Microsoft 365 authentication tokens, risking unauthorized access to school cloud data.
What to do now
Enforce phishing-resistant MFA and conditional access, block legacy auth, train staff to verify IT/passkey requests, review Entra sign-in logs, revoke suspicious tokens, and verify with Microsoft advisory.
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.