🧭 Decision Radar
Relevance for Algeria
Medium
▾
Infrastructure Ready?
Partial
▾
Skills Available?
Partial
▾
Action Timeline
Immediate
▾
CISOs, IT helpdesk teams, Bank of Algeria and financial-sector security teams, enterprise Microsoft 365 administrators
Decision Type
Operational
▾
Quick Take: Algerian organizations running Microsoft cloud services should immediately brief staff that legitimate IT support never initiates unsolicited calls demanding urgent passkey or MFA changes — this single awareness update closes the actual weak point in a campaign that otherwise defeats even phishing-resistant authentication.
How the Passkey-Themed Attack Works
Microsoft’s security research team disclosed the campaign on September 9, 2026, describing an active cloud-based intrusion effort that has been running since May 2026. The attack begins with identity-focused social engineering rather than a technical exploit: threat actors call or message a target’s personal phone number, impersonating the organization’s IT help desk and creating urgency around updating a passkey, multi-factor authentication, or single sign-on configuration to avoid access disruption.
Victims who comply are directed to phishing sites that closely mimic legitimate Microsoft sign-in pages. According to Microsoft’s disclosure, “the passkey narrative serves as a convincing pretext to guide victims through adversary-in-the-middle (AiTM) phishing or device-code authentication flows” — meaning the attackers use the victim’s own trust in the passkey-setup process to walk them through steps that actually hand over session access to the attacker. The phishing infrastructure uses domains designed to look credible, following patterns like “secure-passkey[.]com,” “integratedsso[.]com,” and “add-passkey[.]com,” registered through the Nicenic registrar and made operational within hours of registration, according to Microsoft’s findings.
Once identity compromise succeeds, Microsoft reports the actors conduct systematic data exfiltration from SharePoint, OneDrive, and Exchange, using automated tools — notably one identified by a “python-httpx” user agent — to extract files and emails over sustained periods spanning hours to days. Microsoft attributes the campaign to multiple threat actors, including groups tracked as Storm-3121 and Storm-3032, with connections to the ShinyHunters and Falcon extortion groups. Security-news outlet The Hacker News, corroborating Microsoft’s disclosure, reports that Storm-3032 is also tracked under the alias UNC6671 and has ties to the BlackFile group’s Helix extortion brand, and that after gaining account access the attackers register their own MFA methods before conducting high-volume downloads via the Microsoft Graph API.
Why Attacking the Passkey Enrollment Process Matters
Passkeys were built to eliminate the specific weakness that made passwords and even some MFA methods phishable: they bind cryptographic credentials to a specific device and origin, making a stolen credential largely useless outside its original context. But this campaign doesn’t attack the passkey cryptography itself — it attacks the human process of enrolling, updating, or recovering passkey access, a step that still depends on a person trusting the legitimacy of the request. That distinction matters: no authentication technology, however strong, eliminates the need for organizations to secure the human processes surrounding it.
1. Treat identity-recovery and enrollment workflows as attack surface, not just the credential itself
Security teams that have invested in phishing-resistant authentication like passkeys should now extend that scrutiny to the enrollment, update, and recovery processes around those credentials — the weakest point in this campaign was never the passkey itself, but the human step of “updating” it.
2. Train staff to verify IT helpdesk contact through a known channel, never an inbound call or message
Because this campaign relies entirely on impersonating IT support via unsolicited phone calls or messages, the most effective and lowest-cost defense is a standing policy: employees should never act on security-configuration requests received via inbound call or SMS, and should instead independently initiate contact with IT through a known, verified channel.
3. Monitor for the specific technical indicators Microsoft has published
With Microsoft having disclosed phishing domain patterns and the “python-httpx” exfiltration signature, security teams running Microsoft 365 environments should treat this as an actionable detection opportunity — reviewing sign-in logs and data-access patterns against these specific indicators, not just waiting for a generic phishing-awareness refresh.
Advertisement
What This Signals About the State of Identity Security
This campaign is a reminder that authentication technology and human process security are two different problems, and strengthening one does not automatically strengthen the other. As passkeys become more widely adopted precisely because they close off older phishing vectors, attackers are demonstrating they will simply move up the chain to the setup and recovery processes that remain human-dependent. [The Hacker News’ reporting lists at least eight distinct phishing domain patterns tied to this campaign, including “passkeyhelpdesk[.]com,” “setupmypasskey[.]com,” and “oktasession[.]com,” underscoring how much of the attackers’ infrastructure investment goes into the enrollment pretext rather than into breaking the passkey credential itself](https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html). Organizations rolling out passkeys or other phishing-resistant MFA should treat this campaign as confirmation that the rollout itself — the enrollment and support processes — needs the same security scrutiny as the technology.
Frequently Asked Questions
How does the passkey-themed social engineering attack actually work?
According to Microsoft’s disclosure, attackers call or message victims impersonating IT helpdesk staff, creating urgency around updating passkey or MFA settings, then direct them to phishing sites that guide them through adversary-in-the-middle authentication flows that hand over session access to the attacker.
Does this mean passkeys are not phishing-resistant after all?
No — the underlying passkey cryptography remains phishing-resistant. This campaign instead targets the human enrollment and recovery process around passkeys, exploiting trust in a claimed “update” request rather than attacking the credential itself.
What data are the attackers stealing once they gain access?
Microsoft reports the actors conduct systematic exfiltration from SharePoint, OneDrive, and Exchange using automated tools, extracting files and emails over sustained periods, and attributes the campaign to threat actors including Storm-3121 and Storm-3032, with ties to the ShinyHunters and Falcon extortion groups.













