Work Expertise Process About Notes Contact on LinkedIn

Note

They called about your passkey

Boards were sold passkeys as the end of phishing.

Microsoft’s September write-up is the correction. Since May they have been watching cloud-account takeovers that start with a passkey story. A call or an SMS to the employee’s personal mobile, claiming to be IT. Update your passkey, your MFA, your SSO, or you will lose access. The link is a lookalike sign-in. The flow is adversary-in-the-middle or device-code. The victim types the code or finishes the prompt. The actor now has the session.

They often never enroll a passkey for the user. Microsoft is explicit: the passkey narrative is the pretext. What they want is a captured cookie or a grant the user approved on their behalf.

Then the quiet part. They add their own authentication methods on the account. Graph API reconnaissance. High-volume SharePoint and OneDrive downloads. Exchange collection over REST. Persistence that survives the password reset someone will do on Monday.

Why the personal phone matters

The call does not go to the corporate desk phone. It goes to the number on LinkedIn, the one in the boarding pass, the one in last year’s stealer log.

If the victim opens the link on that personal mobile, Microsoft Defender for Endpoint never sees it. Helpdesk looks at the laptop later and finds nothing. The tenant audit log is where the story actually is: new auth method, impossible travel that is really a proxy, a Graph client that suddenly listed every file.

This is why “we rolled out passkeys” and “the CEO’s Gmail is in a stealer dump” are the same week. One is the corporate identity. One is the personal surface that still answers the helpdesk call.

What to revoke, in order

The methods they added. Not just the password. Look for new FIDO, new authenticator apps, new phone numbers, new app passwords. If you only rotate the password, they still hold a method.

The sessions. Sign out everywhere. Refresh tokens. The AiTM cookie is the door they walked through.

The mailbox rules and the OAuth apps. Collection through Graph does not always look like a forwarding rule from 2018. It looks like a first-party-looking client pulling Exchange and SharePoint at volume.

The personal number as a recovery channel. If IT never owned that SIM, treat it as hostile until the exec has a number that is not in every leak.

Do not have the same helpdesk call them back to “walk them through a real passkey reset” on the same device, in the same hour. That is how you train the next victim.

If the caller already got the code: this is a tenant incident, not an awareness poster. Counsel first if it is an officer. Then identity, then the dump of what Graph touched. The passkey was marketing. The grant was the breach.

Cite: Fabio Correia, “They called about your passkey”, 2026-09-18. https://www.fabiocti.com/notes/they-called-about-your-passkey/. Markdown: https://www.fabiocti.com/notes/they-called-about-your-passkey.md

Comments

Public thread on the canonical URL. GitHub login keeps this off a spam hole; replies are copied here on the next build so crawlers and models see them in the HTML.

No public replies yet.

Add a comment
All notes