Microsoft reports calls, texts, and Teams messages that led to cloud identity compromise in observed intrusions. Users should avoid the message’s link and report any interaction through a trusted channel.
In 60 seconds
- Microsoft cloud account users should care, especially after an unexpected passkey, sign-in, or account-verification request.
- Think back to calls, texts, or Teams messages, then ask the account administrator to check unfamiliar sign-ins or new login methods.
- Do not use the message’s link or approve a code; contact the organization through a phone number or address you already trust.
- For confirmed compromise, administrators should remove unauthorized login methods and end active sign-ins after validating the user and account.
What users should do today
This report matters to people and organizations that use Microsoft cloud accounts. An unexpected call, text, or Teams message about setting up a passkey, updating sign-in protection, or avoiding an account problem deserves caution.
Do not use the message’s link. Do not approve a sign-in or enter a code because someone on the phone tells you to. Contact the organization’s help desk through a phone number or email address you already know. Tell them when the message arrived and whether you clicked, entered information, or approved anything.
To tell whether this situation may affect you, think back to recent passkey or account-verification requests. For an organization, an administrator should check unusual sign-ins and unfamiliar authentication methods, which are the extra ways an account can approve a login.
A personal phone may be involved because Microsoft says some calls and messages went to employees’ personal mobile numbers. That does not by itself show that the phone or account was compromised. It is a reason to report the contact through a trusted channel.
How Microsoft says the intrusions begin
Microsoft Security Research says it has observed active cloud-based intrusions involving multiple accounts since May 2026. The reported pattern starts with an unusual sign-in after a passkey-themed message, then may include a new login method, searches through cloud services, and access to files or email.
The passkey story may be a pretext rather than the real goal. In one method, a fake sign-in page passes the victim’s login details and active sign-in to the attacker. In another, the victim enters a code on a real Microsoft page and unknowingly authorizes an attacker-controlled application.
After gaining access, the attacker may add a phone number, authenticator app, or software-based one-time-password token as an authentication method. This can provide another way to complete future sign-ins. Microsoft also describes a pattern in which attackers used stolen credentials and an authenticator method added earlier.
Microsoft describes searches for users, groups, permissions, applications, files, and mailboxes. Later activity included high-volume access to SharePoint and OneDrive files, along with email and attachment searches in some cases. A sign-in record alone does not prove that a particular file was opened or downloaded, so exposure must be checked account by account.
What account administrators should review
Microsoft recommends treating the activity as a connected sequence instead of judging one event by itself. Review unusual sign-ins together with newly registered authentication methods, searches through Microsoft Graph, and unusual file or mailbox activity.
Microsoft Graph is a set of connections that lets applications work with Microsoft cloud data. Microsoft says administrators should look for broad or program-like searches involving user directories, groups, roles, applications, SharePoint, OneDrive, mail, or attachments. A single ordinary request is not proof of an attack; the pattern across the same account, application, or sign-in session matters more.
Administrators should compare cloud file and email activity with identity records. Microsoft reports that the activity sometimes used changing internet addresses and automated tools, so one address or web domain may not reveal the full sequence. The report also says a tool’s user-agent label, which identifies the software making a request, should not be judged by itself.
For a confirmed compromise, Microsoft recommends validating the user, removing unauthorized authentication methods, and revoking active sessions and refresh tokens. A session is an active sign-in. A refresh token is a digital permission that can help keep that sign-in working. Administrators should then review related file, email, and identity records for the affected account.
What Microsoft’s report says about the operators
Microsoft Threat Intelligence assesses that the initial access activity is used by a range of threat actors, including operators Microsoft tracks as Storm-3121 and Storm-3032, as well as others.
That assessment applies to the activity Microsoft examined. It does not mean every passkey-themed message came from one operator, or that receiving such a message proves an account was compromised.
The report describes observed intrusions and detection ideas. It identifies no software version that needs a patch. The practical first step is to report the message and check the account if the user followed its instructions or account records show unusual activity.
Does this affect me?
- Who may be affected
- People and organizations that use Microsoft cloud accounts, including employees whose personal phones receive these calls or messages. The report concerns account compromise through deception, not a confirmed flaw in a particular product version.
- How to check
- Think back to unexpected calls, texts, or Teams messages about passkeys, sign-in protection, or account verification. Administrators should review unusual sign-ins and unfamiliar newly added authentication methods.
- What to do
- Stop using the message or website and contact the organization through a known help desk channel. Administrators should investigate if the user entered information or approved a code.
- What to avoid
- Do not approve an unexpected sign-in, enter a code for someone else, or trust a web address just because it includes the organization’s name.
Common questions
Does receiving a passkey-themed message mean my account was compromised?
No. Microsoft describes the message as an opening tactic, not proof of compromise. The account needs investigation if the user followed the instructions, entered a code, approved access, or if records show an unusual sign-in or new authentication method.
What should an organization do if an employee followed the request?
Microsoft recommends investigating identity and cloud activity as one sequence. After validating the user and confirming unauthorized access, administrators should remove unauthorized authentication methods, revoke active sessions and refresh tokens, and review file, email, and sign-in activity.
Can a familiar-looking Microsoft sign-in page still be part of the intrusion?
Yes. Microsoft says some cases used a fake page that passed the login session to the attacker. Other cases used a real Microsoft page where the victim entered a code that authorized an attacker-controlled application.
Does a new authentication method prove that files were taken?
No. It is an important sign of possible continued access, but it does not by itself prove that files or email were opened or downloaded. Administrators need to compare identity, mailbox, and cloud-file records.
Primary source
Based only on Microsoft Security Research’s report, “Passkey-themed social engineering leads to identity and cloud compromise,” published September 9, 2026: https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/ Read the complete original source.
Concerned this may affect your computer or account?
Bring the exact alert, device, product, and timeline. Leon will help separate urgent action from noise.
Article history: Published Sep 9, 2026 at 2:46 pm EDT. Updates and corrections are noted here when material facts change.
