Passkey-themed phishing attacks lead to Microsoft 365 data theft
Reddit r/deeplearning3d4 min read
Researchers documented a phishing campaign that impersonated passkey registration prompts, captured live session tokens after users authenticated through legitimate MFA flows, and then used those tokens to access Microsoft 365 tenants with full account privileges (Bleeping Computer). Victims had no indication anything was wrong. The attacker's session looked identical to a normal user session — same permissions, same scope, same API calls. The uncomfortable part: passkeys were the thing being used as bait precisely because users have been trained to trust that flow. The attack didn't break aut
