
Findings and evidence
Microsoft reports cloud intrusions in which unusual sign-ins were followed by added authentication methods, Microsoft Graph activity and access to collaboration data. The source describes social engineering themed around passkeys and account maintenance.
Why it matters
Correlate authentication-method changes, session history and resource access when reconstructing an account compromise. A successful sign-in record alone cannot explain what happened afterward.
Scope and limits
The campaign imitates security procedures; it is not evidence of a cryptographic break in passkeys. Microsoft’s sequence is an investigative pattern, not an automatic verdict for every matching event.
Primary source
Microsoft Security: original publication. Source published 2026-09-09. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.