← Blog

Nobody from IT will call your mobile about a passkey

Tenant Strike5 min read

Microsoft documented a campaign that opens with a call to an employee's personal phone about a passkey. Changing the password afterwards doesn't end it.

He calls the office manager's mobile at ten past four. He knows where she works, and he uses your IT company's name. There's a change going through on the Microsoft account, he says — she needs to set up a passkey before the end of the day or she'll be locked out in the morning. A text arrives with a link while he's still talking. The page it opens looks exactly like the Microsoft sign-in screen, because it was built to.

What makes this work is that it isn't far-fetched. Since September 1, Microsoft has been switching passkeys on automatically for anyone still using text-message codes, and prompting those people to register one. The call sounds like something that was already going to happen.

What Microsoft found

Microsoft's threat researchers published their analysis on September 9, covering intrusions they have tracked since May. The opening is always the same shape: a call or a text to an employee's personal phone number, from someone claiming to be the IT help desk, saying a passkey or a multi-factor setting has to be updated immediately or access will break. Then a link, to a page dressed as the Microsoft sign-in screen.

Arctic Wolf documented the same pattern six days earlier and adds a detail worth knowing: the calls go to directors, vice presidents and IT staff. At a twenty-person company that probably means you, whoever handles the money, and whoever your IT provider actually deals with.

The tell is where it reaches you

One rule cuts through all of this, and it's short enough to say at a stand-up.

A real passkey prompt appears inside Microsoft 365, after you have signed in yourself and completed your usual security check. That is the moment Microsoft's own documentation describes. Not a phone call, and not a text to a personal mobile.

Arctic Wolf's advice to its customers is to tell staff plainly that internal IT will "never cold-call or text users to register passkeys" — good wording to borrow.

They aren't after your passkey

Microsoft's finding is that the passkey story is only a pretext. In most of the cases it examined, enrolling a passkey was never the point.

The fake sign-in page is a relay. Whatever gets typed into it passes straight through to the real Microsoft, so the password works, the approval on the phone works, and nothing on screen looks wrong. What the attacker keeps is the signed-in session that comes out the other end. Passkeys aren't the weakness here — they're the thing being steered around.

The part that catches people out

Once inside, Microsoft found, the attacker's first move is to register a sign-in method of their own on the account: a new phone number, an authenticator app, or a software token. A phone that isn't your employee's is now sitting on her account as a legitimate way of proving she's her.

That matters on the day it happens, because the instinct when someone realises the call was fake is to change the password and breathe out.

Microsoft's assessment is that a complete reset does close it — new password, every session signed out, the added method removed. A password change on its own is not that. The extra method stays. If the attacker still holds a live session, or gets the password again months later, the security prompt is one they can now answer themselves.

So it's three steps, not one: change the password, sign the account out of everywhere, then open the account's sign-in methods and delete anything nobody recognises. We've written out the full recovery sequence.

If nobody catches it, what follows is quiet. Microsoft observed steady downloading from SharePoint, OneDrive and mailboxes, deliberately paced at under a thousand files an hour so it blends into ordinary use, and running anywhere from several hours to several days. Arctic Wolf reports no ransomware and nothing encrypted: the files are simply taken, and by its account an extortion email follows within hours, carrying a 72-hour deadline.

Three things this week

Give your team the sentence, and a number to call. "Nobody from IT will ever ring or text your personal phone about a passkey or a sign-in problem. If someone does, hang up and call me." Then make sure they have your number and your IT provider's real one somewhere they can find in a hurry. This scam depends on there being no easy way to check.

Ask your IT provider to alert you when a new sign-in method is registered. Ask for it by name: notify us whenever anyone registers a new authentication method. It's the event that separates an unsettling phone call from a quiet theft that runs for days before anyone notices.

Ask them to switch off the device code sign-in flow. It's a genuine feature, meant for signing in on things without a proper keyboard — you type a short code somewhere else to approve. Attackers like it because the approval happens on Microsoft's real page, so nothing looks wrong to the person doing it. Microsoft's recommendation in the same write-up is to block it unless there's a specific business reason to keep it.

Those last two come down to settings nobody opens. A read-only scan from Tenant Strike grades how your Microsoft 365 is configured, A to F, and shows the fix for each gap it finds — it reads your settings and never changes them.

AI-researched from public sources, human-reviewed on September 22, 2026. We label AI-assisted writing — see our trust page.

See your own risk

Want this for your own Microsoft cloud?

Tenant Strike finds the security gaps in your Microsoft 365 and Azure, shows how they chain into a real break-in, and hands you a plain-English fix for every one — read-only, and it never asks for permission to change anything. Start a 7-day Pro trial — no credit card.