PULSE the living trend engine
▲ Peaking Technology

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Attackers are using passkey-themed social engineering and voice calls to breach Microsoft 365 accounts and steal corporate data.

5sources
5articles
3velocity
+0%since first seen
1h agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

The brief

A new wave of phishing attacks is targeting Microsoft 365 accounts, utilizing passkey-themed social engineering to facilitate identity and cloud compromise. According to reports from BleepingComputer and Microsoft, these campaigns are designed to steal data from cloud environments. The attacks specifically employ a tool known as the N0va Phishkit, which eSecurity Planet reports is currently targeting users across North America and Europe. These operations focus on manipulating users into providing credentials or access through deceptive Microsoft login interfaces. Coverage from Help Net Security and Dark Reading emphasizes a specific tactic where attackers place voice calls to the personal phones of employees.

This approach exploits Bring Your Own Device (BYOD) policies to bridge the gap between a user's personal hardware and their corporate Microsoft 365 account. By leveraging these phone calls, attackers are able to bypass traditional security perimeters and reach sensitive corporate data. These outlets highlight that the human element of social engineering remains a primary vulnerability even as technical authentication methods evolve. This trend is significant because it targets passkeys, which are generally viewed as a more secure alternative to traditional passwords. The shift toward passkey-themed phishing indicates that attackers are adapting their narratives to match current security trends to better deceive employees.

By mimicking the language of modern authentication and using direct voice communication, the actors are able to create a sense of urgency and legitimacy. The use of the N0va Phishkit demonstrates a structured approach to targeting specific geographic regions including Europe and North America. Future developments will likely center on how organizations mitigate the risks associated with BYOD and personal phone usage in the corporate authentication chain. Since Microsoft has explicitly linked these passkey-themed social engineering efforts to cloud compromise, monitoring for unusual login activity within Microsoft 365 environments will be critical. The focus remains on the intersection of voice-based social engineering and the exploitation of cloud identities to gain unauthorized access to corporate datasets.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 1h ago.

Quick answers

What is the N0va Phishkit?

It is a phishing tool used to target Microsoft logins in North America and Europe.

How are attackers reaching employees?

Attackers are making voice calls to employees' personal phones to exploit BYOD policies.

What is the ultimate goal of these attacks?

The attacks aim to achieve identity and cloud compromise to steal Microsoft 365 corporate data.

Coverage (5)

Topics

Related trends

\n \n \n \n \n \n \n