How the Scam Works Mechanically

Cyber extortion groups linked to syndicates like ShinyHunters and Helix are deploying sophisticated social engineering schemes centered around modern authentication technology. Rather than targeting vulnerabilities in passkey protocols themselves, the threat actors exploit human trust by posing as corporate IT support personnel. Attackers conduct in-depth reconnaissance using professional profiles and organizational charts to identify specific employees before initiating contact via phone calls or SMS messages.

Victims are told that they must immediately configure or synchronize a passkey, single sign-on profile, or multi-factor authentication setting to maintain access to corporate systems. The scammers then direct targets to adversary-in-the-middle phishing portals hosted on lookalike domains such as passkeyhelpdesk or secure-passkey, often appending the victim company name as a subdomain. When employees submit their credentials, the intermediary infrastructure captures session tokens in real time, effectively neutralizing standard two-factor authentication.

In alternative scenarios, attackers abuse Microsoft's legitimate device-code authentication framework. The scammer provides a temporary code and instructs the target to enter it on an official Microsoft login URL. Once authorized by the employee, an access token is issued directly to an application controlled by the intruder, granting comprehensive entry across connected enterprise services, cloud repositories, and email accounts.

Once initial access is established, the intruders systematically entrench themselves. They register secondary authenticator apps or phone numbers under their control to maintain persistent access. Using automated tools and API queries via Microsoft Graph, they map internal directories and stealthily exfiltrate sensitive files from SharePoint, OneDrive, and Exchange over multiple days while keeping request rates low to avoid triggering automated security alarms.

Warning Signs & Red Flags

  • Unsolicited phone calls or text messages from individuals claiming to be internal IT personnel demanding urgent passkey or security profile setup.
  • Directives to enter a specific alphanumeric authorization code into an official Microsoft device login portal at the request of a caller.
  • Login URLs featuring unusual domains that incorporate security buzzwords like 'passkey', 'oktasession', or 'keysyncos' alongside your organization's name.
  • Urgent communications warning of immediate account termination or loss of system access if an authentication task is not performed on the spot.
  • Prompts requesting multi-factor approval or authenticator codes while communicating live with someone claiming to assist with account maintenance.

How to Protect Yourself & Report

Defending against passkey-themed social engineering requires verifying all identity-related requests through secondary, out-of-band channels. Never click links sent via SMS or follow live phone instructions to sign into portals or approve device codes. If contacted by someone claiming to represent IT or internal help desks, terminate the call immediately and reach out to your organization's verified security team through known internal channels.

Organizations should adopt hardware-bound, phishing-resistant FIDO2 authentication keys, enforce device management compliance policies for accessing sensitive cloud tenants, and disable device-code authorization flows across accounts where they are not strictly required. If an account is suspected of compromise, administrators must immediately terminate all active sessions, revoke OAuth tokens, audit registered multi-factor devices for unauthorized entries, and report the intrusion to internal security operations and relevant regulatory authorities.