Microsoft Warns of IT Support Impersonation and Fake Passkey Attacks on M365
Moyen · Hackread ·
En bref
- Attackers impersonate IT support and use fake passkey lures to target Microsoft 365 accounts.
- The objective is to steal authentication tokens and gain access to corporate cloud data.
- K-12 districts using Microsoft 365 may hold sensitive student and staff information at risk.
- No CVE is linked; the threat relies on social engineering and trust in passkey setup.
- Verify unexpected IT support contacts and monitor for new authentication method registrations.
Microsoft is warning organizations about a social engineering campaign that targets Microsoft 365 accounts. Attackers reportedly impersonate IT support staff and present a fake passkey setup or reset scenario. The goal is to trick users into handing over authentication tokens or approving malicious authentication requests. No CVE is tied to this activity, which suggests the weakness is human trust rather than a software flaw.
K-12 districts that rely on Microsoft 365 for email, Teams, SharePoint, and student records are in scope. A stolen token can let an attacker read mail, download files, send messages as the victim, and move laterally without needing the password. Because tokens can survive a password reset, the impact can last until sessions are revoked. Staff, faculty, and even students with cloud accounts could be targeted.
The fake passkey angle is notable. Passkeys are promoted as a phishing-resistant replacement for passwords, so attackers may try to abuse that trust by asking users to set up or fix a passkey through a lookalike page. If a victim follows the instructions, the attacker may capture a session token or register their own authentication method. This can bypass traditional MFA prompts that rely on one-time codes or push approvals.
For schools, the risk includes unauthorized access to sensitive student data, financial systems, and internal communications. A single compromised account can be used to phish other staff or students from a trusted address. The campaign also highlights the need to protect token issuance and authentication method registration, not just passwords.
Watch for reports of unexpected IT calls, emails, or chat messages about passkeys, MFA resets, or account verification. Districts should verify through known channels, monitor for new passkey or MFA method registrations, and be ready to revoke sessions quickly. Microsoft's warning should prompt a review of Conditional Access policies and helpdesk identity verification.
À faire maintenant
- Enable phishing-resistant MFA such as FIDO2 security keys or Windows Hello for staff and privileged accounts, and phase out SMS or voice codes.
- Configure Conditional Access to block legacy authentication and restrict token issuance to compliant or managed devices where possible.
- Train users to verify unexpected IT support requests through a known internal phone number or ticket system, and never approve MFA prompts or share codes.
- Monitor Microsoft 365 audit logs for anomalous token issuance, impossible travel, new passkey registrations, and mailbox rule changes.
- Revoke suspicious sessions and reset credentials immediately when a fake passkey or IT support contact is reported.
- Limit helpdesk ability to reset MFA or register new authentication methods without strong identity verification of the requester.
- Ensure unified audit logging is enabled and review alerts for authentication method changes on high-risk accounts.
Source originale
Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.