Hackers are now using passkeys as bait to target Microsoft 365 accounts.
The scam is pretty simple:
>Attackers pretend to be IT support and tell employees they need to set up or update a passkey.
>They then send them to a fake Microsoft login page.
>The page looks legitimate, but itโs actually designed to trick people into giving the attackers access to their account.
>Once they get in, hackers can add their own way to log in and keep access searching through emails, SharePoint and OneDrive files and steal sensitive company data.