Passkey-themed phishing attacks lead to Microsoft 365 data theft
This story is from 2026-09-12. It is preserved in the archive; the latest stories are on the live feed.
Researchers documented a phishing campaign that impersonated passkey registration prompts, captured live session tokens after users authenticated through legitimate MFA flows, and then used those tokens to access Microsoft 365 tenants with full account privileges (Bleeping Computer). Victims had no…
Read the full story at r/deeplearning ↗
Timeline · 1 report
- 2026-09-12 22:37 · r/deeplearning
Passkey-themed phishing attacks lead to Microsoft 365 data theft