← Back to blog Cybersecurity

Passkey phishing is hijacking Microsoft 365 accounts: how to protect the email of your Mexico operation in 2026

3 min read

On September 11, 2026, BleepingComputer reported a phishing campaign dressed up as a Microsoft notice: ‘register your passkey’. Two days later The Hacker News confirmed the goal: hijack Microsoft 365 accounts and pull whatever sits in SharePoint and OneDrive.

If your company runs a Mexican plant, warehouse or sales office on the same Microsoft 365 tenant as headquarters, this lands on your desk. A passkey is a login key stored on a phone or laptop that replaces the password. Good technology. The trick is getting a user to approve a sign-in that is not theirs, and at that point neither MFA nor the passkey helps.

What the scam looks like

An email that looks like Microsoft It asks the user to register a passkey before access expires. The button opens a sign-in flow that ends up in the attacker's hands.

The email carries the Microsoft logo and a deadline: ‘your organization now requires passkeys, register today’. The accountant in Querétaro clicks, sees the usual sign-in screen and approves.

What they approved was someone else’s access. From then on the attacker signs in as that person, no password needed, and downloads contracts, payroll files and whatever the OneDrive holds.

In our experience the hook works because it sounds like corporate policy. Mexican staff often get IT notices from a headquarters they never talk to, so an English email with a deadline feels normal.

What to check in your tenant today

One hour with a global admin role Sign-in logs, consented apps and forwarding rules: the three places an intruder hides.

Before buying anything, there are three places where an intruder hides. Any global admin can review them in an hour, from any country.

WhereWhat to look forRed flag
Sign-in logsCountry, time and device of each accessSign-ins from countries where you have no staff, or at 3 a.m. Mexico time
Enterprise applications with consentApps a user allowed to read mail or filesGeneric names nobody remembers approving
Mailbox forwarding rulesOutlook rules that copy or move messagesForwarding to external addresses or rules that delete ‘invoice’ emails

OAuth consent deserves a sentence: it is the permission a user gives an app to act with their account without asking for a password. An attacker who gets that consent survives a password reset.

MFA that survives phishing

MFA is the second factor: something you have, besides the password. Not all second factors are equal.

MethodSurvives this campaign?Why
SMS codeNoIntercepted or simply asked for
App push notificationPartlyA tired user approves without reading
Passkey or FIDO2 key bound to the real domainYesOnly works on the legitimate Microsoft site

The irony: a properly configured passkey is exactly what stops this. It will not work on a fake site. What breaks it is approving the registration of someone else’s passkey. So enrollment should happen in the office, with a technician, never from an email link. For a Mexico site that means local hands: we deliver FIDO2 keys and enroll them in person.

Password next to a hacked screen
Password next to a hacked screen
The password is no longer the door. A careless approval is. Fotos: Santeri Viinamäki · CC BY-SA 4.0 · Wikimedia Commons / Pexels

Conditional access and a hardened tenant

Rules that decide who gets in and from where Conditional access blocks sign-ins from countries, devices or apps you do not recognize.

Your tenant is your Microsoft 365 space, where users and mailboxes live. Conditional access is a set of rules that decide from where, on which device and with which method someone may sign in.

With it you can require phishing-resistant MFA for admins, allow sign-ins only from the countries where you operate, Mexico included, and restrict security-method registration to the office network.

Licensing matters here: several of these features depend on the plan. This Microsoft 365 license audit guide helps you see what you own and what you pay for without using. We run that audit as part of licensing for our clients’ Mexican entities.

A different vector than the fake technician

We recently covered fake IT support calls via Teams and Quick Assist. That scam needs a conversation. This one needs an email and a click.

And once inside, the first thing an attacker looks for is your backups. Worth rereading how to make backups that actually restore.

ProcessBi team reviewing a Microsoft 365 tenant
Tell us how your Mexico team uses Microsoft 365 and we will say what to close first Foto: Pexels

What about your Mexico operation?

If nobody has reviewed sign-ins and consented apps since the Mexican entity was set up, that is the starting point.

At ProcessBi licensing, tenant hardening and incident response sit inside the support plan, with a written SLA, Spanish-speaking hands on site and invoicing in MXN or USD.

Book your free assessment — we reply the same business day.

Your path

Running IT in Mexico from abroad

7 of 32
  1. Smart hands ✓ Read You are here 2 min
  2. Remote support ✓ Read You are here 3 min
  3. Nearshoring checklist ✓ Read You are here 2 min
  4. Retail rollouts ✓ Read You are here 2 min
  5. Fake IT support ✓ Read You are here 3 min
  6. Backups that restore ✓ Read You are here 3 min
  7. Secure M365 ✓ Read You are here 3 min
  8. Windows 10 deadline ✓ Read You are here 4 min
  9. Audit app access ✓ Read You are here 3 min
  10. CEO fraud ✓ Read You are here 4 min
  11. Office 2016 cutoff ✓ Read You are here 3 min
  12. Patch today ✓ Read You are here 4 min
  13. Patch VMware ✓ Read You are here 4 min
  14. Office 2021 EOL ✓ Read You are here 3 min
  15. Starlink for sites ✓ Read You are here 3 min
  16. Cardless access ✓ Read You are here 4 min
  17. Control AI on PCs ✓ Read You are here 4 min
  18. ScreenConnect flaw ✓ Read You are here 4 min
  19. Server 2022 EOL ✓ Read You are here 3 min
  20. Exposed cameras ✓ Read You are here 3 min
  21. Domain trust fix ✓ Read You are here 4 min
  22. Patch Cisco ISE ✓ Read You are here 3 min
  23. Protect the plant ✓ Read You are here 3 min
  24. Move to 25H2 ✓ Read You are here 4 min
  25. Outages and UPS ✓ Read You are here 3 min
  26. IT maintenance ✓ Read You are here 4 min
  27. Third-party scripts ✓ Read You are here 3 min
  28. License audit ✓ Read You are here 4 min
  29. Bajío fiber corridor ✓ Read You are here 3 min
  30. Check Point flaw ✓ Read You are here 4 min
  31. Cashless payments ✓ Read You are here 3 min
  32. AI that hacks alone ✓ Read You are here 3 min
  33. Field services
Next Windows 10 a year after end of support: what to do in your Mexico operation before ESU year one ends in October 2026