Show Notes
Follow on LinkedIn: linkedin.com/company/idtheftcenter/
Follow on Instagram: instagram.com/idtheftcenter/
Follow on Facebook: facebook.com/IDTheftResourceCenter/
Follow on X: twitter.com/IDTheftCenter
Follow on TikTok: www.tiktok.com/@idtheftcenter_
Follow on YouTube: www.youtube.com/@IDTheftCenter
Show Transcript
Welcome to the Identity Theft Resource Center's “Weekly Breach Breakdown” for Friday, October 2, 2026. I'm Tatiana Cuadras, Communications Assistant for the ITRC. Thanks to SentiLink for their continued support of the podcast and the ITRC. Each week, we look at recent events and trends related to data security and privacy. This week, we're talking about a passkey scam where criminals pose as your IT department, and why that call from 'IT' may not be what it seems.
Let's start with how it begins. An employee receives a call on their personal phone from an identity criminal claiming to be with the company's IT helpdesk. The caller sounds professional and convincing. They explain that the employee's passkey, multi-factor authentication or single sign-on settings need to be updated immediately to avoid disruption. No employee wants to be locked out of their email during a busy work week, right?
That's exactly what these identity criminals are counting on. Microsoft Security Research says it has been tracking this passkey scam since May, and that the scam generally unfolds in three steps.
- First, the identity criminal directs the employee to do one of two things. In some cases, they send the employee to a fake Microsoft sign-in page that captures their login details and the session information that keeps them signed in. In others, they send the employee to a real Microsoft page and ask them to enter a code. This page is legitimate, but that code that they enter authorizes the scammer's device to access the employee’s account.
Attackers have also used accounts that they already compromised in the past to send these messages through Microsoft Teams, so the request appears to come from a trusted email from your colleague. - Next, once the identity criminal is inside your account, they can register their own login methods on the account, such as their own phone numbers and authenticator apps. Think of it like letting a stranger into your house and them secretly making a copy of your house key. Because of this, the next time your account asks for verification, the attacker can respond without you ever knowing.
- Lastly, once the identity criminals are inside your account, they map out the organization, including its users, teams and systems, then move into SharePoint, OneDrive and email to access files and messages.
It's important to note that passkeys themselves are not the problem. As Jon Baker of AttackIQ explained, "The passkey in this campaign is the lure, not the weakness." He added that the multi-factor authentication attackers got around could be phished, and that genuine passkeys would have stopped the attack. So, passkeys are still recommended; identity criminals are just borrowing their name tag.
Microsoft recommends that organizations require phishing-resistant multi-factor authentication and block code-based sign-in methods where there's no business need for them. It also advises security teams to watch for warning signs that appear together, such as an unusual sign-in followed by a newly added login method or unexpected activity in files and email.
If you want to know more about how to protect your identity, learn more about passkeys, or if you think your information or identity has been misused, you can speak with an expert ITRC advisor on the phone, chat live on the web or exchange emails during our normal business hours, Monday through Friday, 6 a.m. to 5 p.m. Pacific time. Just visit idtheftcenter.org to get started.
Thanks again to SentiLink for their support of the ITRC and this podcast. Please hit the like button for this episode, and subscribe wherever you listen to podcasts. We'll be back next week with a new episode of the “Weekly Breach Breakdown”. I'm Tatiana Cuadras. Until then, thanks for listening.