Fake IT Helpdesk Alerts Used to Compromise Microsoft 365 Accounts, Researchers Warn
Microsoft Security researchers have identified a coordinated social‑engineering campaign in which threat actors pose as corporate IT support staff to trick users into surrendering access to their Microsoft 365 accounts.
The attackers send convincing emails that appear to come from an internal helpdesk, warning recipients that their account security is at risk and urging them to click a link to verify a "passkey" alert. The link leads to a counterfeit login page that captures the user’s credentials and, in many cases, the one‑time passcode required for multi‑factor authentication (MFA).
Once the credentials are harvested, the intruders use the compromised account to establish persistent MFA tokens, allowing them to maintain access even after the original password is changed. With a foothold in the environment, they systematically harvest data stored in SharePoint, OneDrive, and Exchange Online, creating a rich cache of corporate documents, emails, and other sensitive files that can be exfiltrated or used for further attacks.
Microsoft’s security team has issued guidance urging organizations to verify any unsolicited IT support requests through separate channels, to educate users about the specific wording used in these phishing messages, and to enforce conditional access policies that limit the creation of new MFA devices from untrusted locations. The company also recommends enabling password‑less authentication methods that are less susceptible to credential‑theft techniques.
The campaign, first reported by the GBHackers community, underscores the evolving sophistication of phishing operations that blend social manipulation with technical exploitation of cloud services. As more enterprises migrate critical workloads to Microsoft 365, security teams are expected to prioritize detection of anomalous login patterns and to adopt zero‑trust principles that reduce reliance on passwords alone.
Comments (0)
Be the first to comment.
Join the discussion