100% money-back guarantee · support Mon–Fri 8:30–17:30
Help
NewsMICROSOFT1 min read

Passkey-themed social engineering: risks to identity and the cloud

Cybercriminals are exploiting social engineering related to passkeys to compromise identities and launch broader attacks in cloud systems.

Social engineering attacks using the theme of passkeys as bait represent a concrete threat to cybersecurity. Malicious actors exploit this technique to compromise user identities and gain initial access, which paves the way for even more extensive and damaging cloud attacks.

Once access is obtained, threat actors establish multi-factor authentication (MFA) persistence. Subsequently, they abuse Microsoft Graph to conduct reconnaissance activities within the system and access sensitive data stored in SharePoint, OneDrive, and email inboxes.

To counter this threat, it is crucial to understand the dynamics of these attacks. Indeed, there are specific guidelines for the detection and mitigation of such illicit activities, useful for protecting corporate infrastructures.

Licences MICROSOFT

More news