Biometrics: Fake Passkey Texts Hijack Microsoft 365
Biometrics: Fake Passkey Texts Hijack Microsoft 365
This episode is based on our article:
Read the full article →Biometrics: Fake Passkey Texts Hijack Microsoft 365
Full Episode Transcript
The phone rings. It's someone from your company's tech support. They sound calm, professional. They tell you your account needs a quick security update, a new passkey, or you could lose access by the end of the day. So you say yes. And in that one word, you just handed a criminal the keys to everything.
If you've ever gotten a message asking you to
If you've ever gotten a message asking you to update your login or set up something more secure, this story is about you. Because that's exactly the moment attackers are now hunting for. According to Microsoft's security researchers, criminals have been running this scheme since May of last year, and it's spreading. They're not cracking passwords anymore. They're not breaking any code. They're calling or texting employees on their personal phones, pretending to be the help desk, and using one simple idea against them, the fear of losing access. So how does a single "yes" open the door to an entire company's files?
Let's start with the pitch itself. The attacker warns you that your passkey or your login is about to expire. There's a deadline. There's urgency. According to the reporting from Biometric Update, that pressure is completely manufactured, but it sounds exactly like the kind of message a real tech department would send. And that's the trick. Who says no to a security upgrade? Turning down protection feels reckless. So people comply. Previously in this series: Biometrics Fake Passkey Texts Hijack Microsoft 365.
Then comes the fake page. Attackers send you to a website that looks nearly identical to a real Microsoft sign-in screen. Sometimes they even slip your own company's name into the web address to make it feel official. In some cases, the message doesn't come from a stranger at all. It arrives through a coworker's Teams account, one that's already been hacked. So the request looks like it's coming from someone you trust.
Here's the part that stings
Here's the part that stings. Microsoft says the attacker's fake site sits quietly in the middle, you type your login, and it passes your details straight to the real Microsoft, capturing everything as it goes. And this is the twist most people miss. The victims often had that extra security check, the code, the tap-to-approve. It didn't save them. Because if that second step isn't the passwordless kind, an attacker can steal the session right out from under it. Multi-factor security you thought protected you became the thing that gave them confidence. Up next: Age Verification Roblox 31 Lawsuits Test Section 230 Podcast.
And once they're in? According to the reporting, that single login can open SharePoint, OneDrive, company email, the whole suite. Then they do something quiet and clever. They register their own login methods, a new phone number, a new authenticator app. So even after you change your password, they still have a way back in. They don't just visit. They move in.
Here's the flip that reframes all of it. The passkey technology itself never failed. Nobody broke the math. The criminals simply borrowed the word "passkey", a word we've been trained to trust, and used it as bait. They weaponized us doing the right thing.
The Bottom Line
So let's bring it home. Criminals are calling and texting people, pretending to be tech support, and using a fake security update to steal their login. The technology isn't broken, the trust is. One rushed "yes" can hand over a company's entire account. Whether you manage a network or just check your work email on your phone, the lesson is the same, when a security prompt shows up out of nowhere, slow down and verify it through a channel you already know. A criminal doesn't always break in. Sometimes they just get you to open the door.
The written version goes deeper, link's below.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Episodes
Google Age Verification: 14 Days Before Accounts Vanish
Google might already have a guess about how old you are — and it didn't get that number from your birthday. It got it from what you search for. From what you watch on YouTube. And if that guess is wrong, you could have ju
PodcastBiometric Verification: 326 Fake IDs Scanned Just Fine
Between twenty twenty-one and this past August, Malaysian authorities logged three hundred and twenty-six cases of fake or misused identity cards. And here's what should stop you cold — many of those cards scanned just fine. The reader lit up
PodcastUK Age Verification: Pubs Now Legal to Take Phone ID
Picture handing your driver's license to a bartender. Now they know your name, your home address, your exact birthday — everything printed on that card. Starting this month in the U.K., you can walk i
