{
  "id": 8498595,
  "title": "Hackers Are Using Passkey Updates as a New Microsoft Phishing Hook",
  "url": "https://urgent.news/2026/09/18/hackers-are-using-passkey-updates-as-a-new-microsoft-phishing-hook",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-18T23:36:28.000Z",
  "source": {
    "name": "TechRepublic",
    "slug": "techrepublic",
    "url": "https://www.techrepublic.com/article/news-microsoft-passkey-phishing-mfa-device-code/"
  },
  "original_language": "en",
  "account": "Hackers are exploiting Microsoft's passkey and MFA update requests to launch phishing attacks, according to Microsoft researchers. These features were intended to make accounts more secure, but attackers have learned to use them for their advantage. The hackers impersonate IT staff and request passkey or MFA updates, tricking employees into following a phishing link or providing authentication information. Once an attacker gains access to an account, they conduct reconnaissance, add authentication methods for persistence, and access sensitive data across services like SharePoint, OneDrive, and Exchange Online. Microsoft recommends that organizations remain vigilant and use a layered approach to identity security, combining phishing-resistant authentication with tighter enrollment controls, session monitoring, and rapid token revocation.",
  "summary": "Microsoft warns attackers are using passkey and MFA update requests to phish employees, hijack sessions, and access Microsoft 365 data. The post Hackers Are Using Passkey Updates as a New Microsoft Phishing Hook appeared first on TechRepublic .",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}