Passkey-themed social engineering: risks for identity and the cloud
Microsoft reports attacks based on passkey-themed social engineering techniques that compromise identities and pave the way for cloud attacks.

Social engineering attacks exploiting the theme of passkeys represent a concrete threat to the security of digital identities. According to reports, malicious actors use these techniques to compromise user identities and launch broader attacks within cloud environments.
Once access is obtained, threat actors establish multi-factor authentication (MFA) persistence. Subsequently, they abuse Microsoft Graph to conduct reconnaissance activities and access sensitive data on SharePoint, OneDrive, and in email inboxes.
