08/26/2026
"'We need you to register a new passkey.' Hang up."
A tactic worth warning your team about this week, because it starts with something people don't expect: a phone call.
Attackers call an employee, claim IT needs them to "register a new passkey," and walk them through a fake Microsoft login page in real time. While they're on the phone, the attacker captures the password and the MFA code β then quietly enrolls their own passkey on the account. That gives them access that survives a password reset.
It works because everyone's been trained to distrust email links. Almost nobody has been trained to distrust a helpful voice.
**The habit that stops it:** if someone calls asking you to register a passkey or verify security settings, hang up and call IT back on a number you already had. Real IT teams don't enroll credentials for you over the phone.
Worth sharing with your staff today.
` `