We covered IT impersonation attacks on TechTips Tuesday earlier this year. At the time, attackers were using email bombing followed by fake Microsoft Teams messages to trick employees into installing malware. That attack worked because it felt like internal IT reaching out to help.
The same playbook is back, but it has evolved in three meaningful ways — and Microsoft just published details on an active campaign that every business using Microsoft 365 needs to understand right now.
What Is Happening
Since May 2026, coordinated criminal groups have been calling employees directly and impersonating their company's IT help desk. The message is urgent: update your passkey or multi-factor authentication settings immediately or lose access to company systems.
What makes this version different from what we covered before is the delivery path. Rather than using company communication tools like Microsoft Teams, these attackers send a phishing link by SMS directly to the employee's personal phone. That step deliberately bypasses corporate security controls and lands the attack in a space employees tend to trust more.
The link points to a fake Microsoft login page that looks convincing enough to fool most people. When the employee enters their credentials and their multi-factor authentication code, both are captured by the attacker in real time.
Before making contact, attackers research each target organization and its employees using publicly available sources like LinkedIn and company websites. The fake login pages they build often include the victim company's own name in the web address to appear more legitimate. Examples of domains used include addresses like passkeyhelpdesk.com, secure-passkey.com, and setupmypasskey.com, with the company's name embedded in the subdomain.
The passkey lure is particularly effective because passkeys are a newer technology that many employees have heard about but are not fully comfortable with yet. Being told to update something unfamiliar, by someone claiming to be IT, under time pressure, is a combination that works.
What Happens After an Employee Falls For It
This is where the current attack diverges most significantly from what we covered before, and it is the part of the story that makes this week's tip urgent even for businesses that have already trained their teams on IT impersonation.
Within minutes of gaining access to a Microsoft 365 account, the attacker checks every application and resource the account can reach. They access the employee's connected applications, profile information, and sign-in history. From there they move into SharePoint Online, Outlook, OneDrive, and any third-party platforms linked through single sign-on, which can include tools like Salesforce, Google Workspace, Dropbox, Slack, and others.
The attackers then add their own multi-factor authentication method to the compromised account, registering a phone number or authenticator app they control. This lets them keep accessing the account independently, even after the employee changes their password, until an administrator fully revokes all sessions and removes the attacker-added authentication method.
Data theft follows, but it is done slowly and deliberately. Rather than downloading everything at once, attackers access fewer than 1,000 files or emails per hour to blend in with normal user activity. In confirmed cases, this phase lasted multiple days before anyone noticed. Microsoft documented systematic access across SharePoint, OneDrive, and Exchange Online in every investigated incident, with the activity appearing automated and specifically designed to avoid triggering security alerts.
Why This Is Harder to Catch Than a Standard Phishing Email
Two things work in the attacker's favor here. The first is the phone call or direct message. An approach that feels personal and involves a live voice or direct contact lowers the guard of employees who have been trained to be skeptical of email attachments but are less cautious with direct communication.
The second is the post-compromise behavior. Because the attacker adds their own MFA method and conducts data theft slowly over multiple days, the breach can be well underway before anything unusual is detected. Standard security tools that look for rapid, high-volume activity may not flag what looks like a normal user accessing files at a normal pace.
What Your Team Should Do Right Now
- Train your team on this specific scenario. Employees should know that IT will never call out of the blue and send a link to a personal phone demanding immediate login to avoid losing access. Any unsolicited contact creating urgency around account access should be verified through a separate, known channel before any action is taken. Call IT back directly using a number already on file rather than responding to the incoming contact.
- Treat any login link sent by SMS as suspicious. Legitimate IT departments managing Microsoft 365 do not send account update links to employees' personal phones. A text message with a Microsoft login link, regardless of how convincing it looks, should always be verified before clicking.
- Review Microsoft 365 sign-in logs for unusual patterns. Sign-ins from unrecognized or unmanaged devices followed immediately by new MFA registrations are one of the clearest indicators of this type of compromise. Catching that pattern early is the difference between a contained incident and a multi-day data theft operation.
- If an account is suspected of being compromised, act immediately and completely. Revoke all active sessions and tokens, reset credentials, and remove any authentication methods the employee did not personally add. Microsoft recommends requiring the affected user to fully re-register their authentication methods from scratch rather than simply resetting a password.
- Consider disabling device-code authentication in your Microsoft 365 environment if your organization does not actively use it. This is one of the specific techniques used in these attacks to maintain persistent access, and disabling it removes that avenue entirely.
- Use phishing-resistant multi-factor authentication wherever possible. Hardware security keys are the strongest option available and are specifically designed to defeat the real-time credential relay techniques these attacks rely on.
This campaign is active right now and specifically targets businesses using Microsoft 365. The attackers research their targets before calling, send phishing links to personal phones to bypass corporate security controls, maintain access by adding their own MFA methods, and collect data slowly over days to avoid detection. Training your team to pause and verify before acting on any unsolicited IT request, and knowing what to look for in sign-in logs, are the most effective defenses available today.
