Microsoft warned on September 9, 2026, that threat actors are running passkey-themed social engineering campaigns to steal user identities and break into cloud services including SharePoint, OneDrive, and email.

According to the Microsoft Security Blog, once attackers compromise an identity, they move to establish multi-factor authentication persistence, giving them durable access to targeted accounts. They also abuse Microsoft Graph for reconnaissance, mapping out resources before extracting data.

The blog said SharePoint, OneDrive, and email data are all accessed as part of the broader intrusion chain that follows an initial identity compromise. Microsoft published both detection and mitigation guidance alongside the warning.