Passkey phishing is hijacking Microsoft 365 accounts: how to protect the email of your Mexico operation in 2026
On September 11, 2026, BleepingComputer reported a phishing campaign dressed up as a Microsoft notice: ‘register your passkey’. Two days later The Hacker News confirmed the goal: hijack Microsoft 365 accounts and pull whatever sits in SharePoint and OneDrive.
If your company runs a Mexican plant, warehouse or sales office on the same Microsoft 365 tenant as headquarters, this lands on your desk. A passkey is a login key stored on a phone or laptop that replaces the password. Good technology. The trick is getting a user to approve a sign-in that is not theirs, and at that point neither MFA nor the passkey helps.
What the scam looks like
The email carries the Microsoft logo and a deadline: ‘your organization now requires passkeys, register today’. The accountant in Querétaro clicks, sees the usual sign-in screen and approves.
What they approved was someone else’s access. From then on the attacker signs in as that person, no password needed, and downloads contracts, payroll files and whatever the OneDrive holds.
In our experience the hook works because it sounds like corporate policy. Mexican staff often get IT notices from a headquarters they never talk to, so an English email with a deadline feels normal.
What to check in your tenant today
Before buying anything, there are three places where an intruder hides. Any global admin can review them in an hour, from any country.
| Where | What to look for | Red flag |
|---|---|---|
| Sign-in logs | Country, time and device of each access | Sign-ins from countries where you have no staff, or at 3 a.m. Mexico time |
| Enterprise applications with consent | Apps a user allowed to read mail or files | Generic names nobody remembers approving |
| Mailbox forwarding rules | Outlook rules that copy or move messages | Forwarding to external addresses or rules that delete ‘invoice’ emails |
OAuth consent deserves a sentence: it is the permission a user gives an app to act with their account without asking for a password. An attacker who gets that consent survives a password reset.
MFA that survives phishing
MFA is the second factor: something you have, besides the password. Not all second factors are equal.
| Method | Survives this campaign? | Why |
|---|---|---|
| SMS code | No | Intercepted or simply asked for |
| App push notification | Partly | A tired user approves without reading |
| Passkey or FIDO2 key bound to the real domain | Yes | Only works on the legitimate Microsoft site |
The irony: a properly configured passkey is exactly what stops this. It will not work on a fake site. What breaks it is approving the registration of someone else’s passkey. So enrollment should happen in the office, with a technician, never from an email link. For a Mexico site that means local hands: we deliver FIDO2 keys and enroll them in person.
Conditional access and a hardened tenant
Your tenant is your Microsoft 365 space, where users and mailboxes live. Conditional access is a set of rules that decide from where, on which device and with which method someone may sign in.
With it you can require phishing-resistant MFA for admins, allow sign-ins only from the countries where you operate, Mexico included, and restrict security-method registration to the office network.
Licensing matters here: several of these features depend on the plan. This Microsoft 365 license audit guide helps you see what you own and what you pay for without using. We run that audit as part of licensing for our clients’ Mexican entities.
A different vector than the fake technician
We recently covered fake IT support calls via Teams and Quick Assist. That scam needs a conversation. This one needs an email and a click.
And once inside, the first thing an attacker looks for is your backups. Worth rereading how to make backups that actually restore.
What about your Mexico operation?
If nobody has reviewed sign-ins and consented apps since the Mexican entity was set up, that is the starting point.
At ProcessBi licensing, tenant hardening and incident response sit inside the support plan, with a written SLA, Spanish-speaking hands on site and invoicing in MXN or USD.
Book your free assessment — we reply the same business day.
Your path
Running IT in Mexico from abroad
7 of 32- Smart hands ✓ Read You are here 2 min
- Remote support ✓ Read You are here 3 min
- Nearshoring checklist ✓ Read You are here 2 min
- Retail rollouts ✓ Read You are here 2 min
- Fake IT support ✓ Read You are here 3 min
- Backups that restore ✓ Read You are here 3 min
- Secure M365 ✓ Read You are here 3 min
- Windows 10 deadline ✓ Read You are here 4 min
- Audit app access ✓ Read You are here 3 min
- CEO fraud ✓ Read You are here 4 min
- Office 2016 cutoff ✓ Read You are here 3 min
- Patch today ✓ Read You are here 4 min
- Patch VMware ✓ Read You are here 4 min
- Office 2021 EOL ✓ Read You are here 3 min
- Starlink for sites ✓ Read You are here 3 min
- Cardless access ✓ Read You are here 4 min
- Control AI on PCs ✓ Read You are here 4 min
- ScreenConnect flaw ✓ Read You are here 4 min
- Server 2022 EOL ✓ Read You are here 3 min
- Exposed cameras ✓ Read You are here 3 min
- Domain trust fix ✓ Read You are here 4 min
- Patch Cisco ISE ✓ Read You are here 3 min
- Protect the plant ✓ Read You are here 3 min
- Move to 25H2 ✓ Read You are here 4 min
- Outages and UPS ✓ Read You are here 3 min
- IT maintenance ✓ Read You are here 4 min
- Third-party scripts ✓ Read You are here 3 min
- License audit ✓ Read You are here 4 min
- Bajío fiber corridor ✓ Read You are here 3 min
- Check Point flaw ✓ Read You are here 4 min
- Cashless payments ✓ Read You are here 3 min
- AI that hacks alone ✓ Read You are here 3 min
- Field services →