CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
Podcast

Biometrics: Fake Passkey Texts Hijack Microsoft 365

Biometrics: Fake Passkey Texts Hijack Microsoft 365

Biometrics: Fake Passkey Texts Hijack Microsoft 365

0:00-0:00

This episode is based on our article:

Read the full article →

Biometrics: Fake Passkey Texts Hijack Microsoft 365

Full Episode Transcript


The phone rings. It's someone from your company's tech support. They sound calm, professional. They tell you your account needs a quick security update, a new passkey, or you could lose access by the end of the day. So you say yes. And in that one word, you just handed a criminal the keys to everything.


If you've ever gotten a message asking you to

If you've ever gotten a message asking you to update your login or set up something more secure, this story is about you. Because that's exactly the moment attackers are now hunting for. According to Microsoft's security researchers, criminals have been running this scheme since May of last year, and it's spreading. They're not cracking passwords anymore. They're not breaking any code. They're calling or texting employees on their personal phones, pretending to be the help desk, and using one simple idea against them, the fear of losing access. So how does a single "yes" open the door to an entire company's files?

Let's start with the pitch itself. The attacker warns you that your passkey or your login is about to expire. There's a deadline. There's urgency. According to the reporting from Biometric Update, that pressure is completely manufactured, but it sounds exactly like the kind of message a real tech department would send. And that's the trick. Who says no to a security upgrade? Turning down protection feels reckless. So people comply. Previously in this series: Biometrics Fake Passkey Texts Hijack Microsoft 365.

Then comes the fake page. Attackers send you to a website that looks nearly identical to a real Microsoft sign-in screen. Sometimes they even slip your own company's name into the web address to make it feel official. In some cases, the message doesn't come from a stranger at all. It arrives through a coworker's Teams account, one that's already been hacked. So the request looks like it's coming from someone you trust.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Here's the part that stings

Here's the part that stings. Microsoft says the attacker's fake site sits quietly in the middle, you type your login, and it passes your details straight to the real Microsoft, capturing everything as it goes. And this is the twist most people miss. The victims often had that extra security check, the code, the tap-to-approve. It didn't save them. Because if that second step isn't the passwordless kind, an attacker can steal the session right out from under it. Multi-factor security you thought protected you became the thing that gave them confidence. Up next: Age Verification Roblox 31 Lawsuits Test Section 230 Podcast.

And once they're in? According to the reporting, that single login can open SharePoint, OneDrive, company email, the whole suite. Then they do something quiet and clever. They register their own login methods, a new phone number, a new authenticator app. So even after you change your password, they still have a way back in. They don't just visit. They move in.

Here's the flip that reframes all of it. The passkey technology itself never failed. Nobody broke the math. The criminals simply borrowed the word "passkey", a word we've been trained to trust, and used it as bait. They weaponized us doing the right thing.


The Bottom Line

So let's bring it home. Criminals are calling and texting people, pretending to be tech support, and using a fake security update to steal their login. The technology isn't broken, the trust is. One rushed "yes" can hand over a company's entire account. Whether you manage a network or just check your work email on your phone, the lesson is the same, when a security prompt shows up out of nowhere, slow down and verify it through a channel you already know. A criminal doesn't always break in. Sometimes they just get you to open the door.

The written version goes deeper, link's below.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search