Microsoft warns that passkey-themed phishing is hijacking Microsoft 365 accounts, adding rogue MFA methods, and slowly stealing business cloud data.
Read more →
This story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.
Under cover of an alleged passkey update, cybercriminal groups trap employees, retrieve their Microsoft 365 sessions and then search SharePoint, OneDrive and Exchange for sensitive data.