Passkey-themed phishing attacks lead to Microsoft 365 data theft
Attackers are using passkey-themed social engineering and voice calls to breach Microsoft 365 accounts and steal corporate data.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A new wave of phishing attacks is targeting Microsoft 365 accounts, utilizing passkey-themed social engineering to facilitate identity and cloud compromise. According to reports from BleepingComputer and Microsoft, these campaigns are designed to steal data from cloud environments. The attacks specifically employ a tool known as the N0va Phishkit, which eSecurity Planet reports is currently targeting users across North America and Europe. These operations focus on manipulating users into providing credentials or access through deceptive Microsoft login interfaces. Coverage from Help Net Security and Dark Reading emphasizes a specific tactic where attackers place voice calls to the personal phones of employees.
This approach exploits Bring Your Own Device (BYOD) policies to bridge the gap between a user's personal hardware and their corporate Microsoft 365 account. By leveraging these phone calls, attackers are able to bypass traditional security perimeters and reach sensitive corporate data. These outlets highlight that the human element of social engineering remains a primary vulnerability even as technical authentication methods evolve. This trend is significant because it targets passkeys, which are generally viewed as a more secure alternative to traditional passwords. The shift toward passkey-themed phishing indicates that attackers are adapting their narratives to match current security trends to better deceive employees.
By mimicking the language of modern authentication and using direct voice communication, the actors are able to create a sense of urgency and legitimacy. The use of the N0va Phishkit demonstrates a structured approach to targeting specific geographic regions including Europe and North America. Future developments will likely center on how organizations mitigate the risks associated with BYOD and personal phone usage in the corporate authentication chain. Since Microsoft has explicitly linked these passkey-themed social engineering efforts to cloud compromise, monitoring for unusual login activity within Microsoft 365 environments will be critical. The focus remains on the intersection of voice-based social engineering and the exploitation of cloud identities to gain unauthorized access to corporate datasets.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 1h ago.
Quick answers
What is the N0va Phishkit?
It is a phishing tool used to target Microsoft logins in North America and Europe.
How are attackers reaching employees?
Attackers are making voice calls to employees' personal phones to exploit BYOD policies.
What is the ultimate goal of these attacks?
The attacks aim to achieve identity and cloud compromise to steal Microsoft 365 corporate data.
Coverage (5)
- N0va Phishkit Targets North America and Europe Through Microsoft Logins eSecurity Planet · 19h ago
- Attackers call employees’ personal phones to break into Microsoft 365 accounts Help Net Security · 19h ago
- Passkey-themed social engineering leads to identity and cloud compromise Microsoft · 19h ago
- Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data Dark Reading · 19h ago
- Passkey-themed phishing attacks lead to Microsoft 365 data theft BleepingComputer · 19h ago
Topics
Related trends
Android rolling out passkey transfers between password managers
Google is introducing a new capability for Android that allows users to transfer passkeys between different password managers with increased ease and safety.
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Fake IT help desk calls and sophisticated phishing kits are targeting Microsoft 365 users globally to bypass multi-factor authentication.
Microsoft (MSFT)’s Outlook and OpenAI’s ChatGPT Work Both Broke the Same Day
Microsoft Outlook and OpenAI's ChatGPT suffered simultaneous outages on the same day, according to recent technology reporting.
Massive Microsoft 365 outage causes auth issues, service failures
Android Authority coverage examines a widespread service failure impacting Microsoft Outlook, OneDrive, and other Microsoft 365 tools.
Microsoft 365 outage drags on, but things are improving
6 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.
Microsoft Outlook Outage Appears Mostly Resolved
1 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.