patch&proof.
← The dispatch

identity / Source brief

Passkey-themed social engineering targeted the enrollment path

Microsoft documented campaigns that used passkey-themed lures, then registered attacker-controlled authentication methods and moved through cloud workload…

Historical backfill · prepared 16 September 2026. Dates below describe the source or event; this is a local review edition.

Passkey-themed social engineering targeted the enrollment path.

What happened. Microsoft documented campaigns that used passkey-themed lures, then registered attacker-controlled authentication methods and moved through cloud workloads. The company associated observed activity with several tracked actor sets while keeping attribution scoped.

Impact and confidence

High confidence in Microsoft’s observed sequence and product telemetry; the post did not establish universal campaign reach or a weakness in passkey cryptography itself.

Defensive takeaway

Protect security-information registration with fresh authentication, managed-device or named-location constraints, risk signals, and connected review of sign-in, enrollment, token, SaaS, and mailbox events.

Evidence & dates

Follow the source.

Preserved from the earlier sourced news desk. This brief is distinct from the newly researched historical articles.

Source published
2026-09-09
Event date
No single confirmed day assigned
Site publication
Unpublished · local review
Passkey-themed social engineering leads to identity and cloud compromise
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval