When a Simple “Update Your Passkey” Message Becomes a Cyberattack
According to a recent report from The Hacker News, cybercriminals are now using fake passkey prompts to trick people into handing over access to their Microsoft cloud accounts. The attackers call or text employees, pretending to be from their IT department, and pressure them to “update” their passkey or multi-factor authentication. Once the employee follows the link, the bad guys steal their credentials or get them to approve a device-code login, giving the attackers full control of the account.
This isn’t just a new trick—it’s a dangerous shift. Passkeys were supposed to make logins safer by replacing passwords. But attackers quickly found a way to weaponize trust in new technology. They research their targets on social media, build fake login pages that look real, and even use Microsoft Teams to spread the scam. For any business using cloud services, this is a wake-up call about how creative and determined cybercriminals have become.
Why the Passkey Scam Is a Smarter, Harder-to-Spot Threat
Traditional phishing relies on a fake email with a suspicious link. The passkey attack is more sophisticated. The attacker first calls the victim on their personal phone, posing as a helpful IT staffer. Then they send a text message with a link to a realistic-looking Microsoft sign-in page. Because the request feels urgent and personal, employees are far more likely to comply without thinking.
What makes this especially worrying is how it bypasses standard security tools. The attackers don’t steal passwords; they trick the victim into approving a device-code or an adversary-in-the-middle connection. That means even if your business uses multi-factor authentication, you can still be compromised. This type of social engineering exploits human nature—our desire to be helpful and our fear of losing access to critical systems.
What This Means for Australian SMBs
Australian small and mid-sized businesses often have fewer cybersecurity resources than large corporations. That makes them prime targets for these passkey phishing campaigns. An employee who receives a call from “IT” about a passkey update might not think to verify the request, especially if the attacker uses the employee’s name and mentions a real colleague. One slip-up could give a criminal access to your entire Microsoft 365 environment—including emails, SharePoint files, and OneDrive documents.
Even if you don’t use passkeys yet, the technique can be adapted to other authentication methods. Attackers are testing these attacks globally, and Australian businesses are not immune. The cost of a data breach—lost customer trust, regulatory fines, recovery expenses—can be devastating for a small business. This is not a problem for “someone else” to worry about. It’s happening now.
What You Can Do Now
- Train your staff to verify IT requests. Teach everyone to hang up and call the IT team directly using a known phone number before making any security changes. No legitimate IT team will ever ask you to click a link from a text message.
- Implement conditional access policies. Require that any cloud login from an unfamiliar device or location triggers a separate approval step, such as a notification sent to your phone via an authenticator app.
- Set up a “break glass” account. Create a separate administrative account that can only be used in emergencies. Monitor all changes to passkey and MFA settings so any unauthorized addition is caught early.
- Use phishing-resistant MFA. Move away from SMS codes and push notifications toward FIDO2 security keys or certificate-based authentication. These methods are much harder for attackers to intercept.
- Run regular simulated phishing tests. Practice sending realistic passkey scam messages to your team. Track who clicks and provide extra training to reduce risk over time.
Security is a moving target. MS&VG helps Australian SMBs stay ahead of threats like passkey phishing by providing practical assessments, staff training, and managed security services. If you’re unsure how your business would handle this kind of attack, reach out for a no-pressure conversation about what steps make sense for you.