Passkey-themed social engineering targeted the enrollment path.
What happened. Microsoft documented campaigns that used passkey-themed lures, then registered attacker-controlled authentication methods and moved through cloud workloads. The company associated observed activity with several tracked actor sets while keeping attribution scoped.
Impact and confidence
High confidence in Microsoft’s observed sequence and product telemetry; the post did not establish universal campaign reach or a weakness in passkey cryptography itself.
Defensive takeaway
Protect security-information registration with fresh authentication, managed-device or named-location constraints, risk signals, and connected review of sign-in, enrollment, token, SaaS, and mailbox events.