
Cybersecurity experts have warned of a new wave of phishing campaigns that exploit advanced protection mechanisms to deceive users. Attackers send fake notifications and requests requesting to update Passkeys or Multi-Factor Authentication (MFA) settings.
These attacks depend on making the victim believe that there is a security threat that requires immediate intervention to update the account, in order to later direct him to practical steps that grant the hackers access powers, or prompt them to agree to malicious and suspicious login processes.
In the same context, Microsoft monitored extensive targeting attempts that targeted vital cloud services such as SharePoint, OneDrive, and Exchange Online. Usually, following a hack, attackers add new authentication methods to establish their control and ensure continued access to the hacked account.
To confront these escalating threats, experts recommend absolutely not responding to sudden requests to update passkeys or two-factor authentication, especially those received via unexpected messages or links. For safety, direct access to account settings through official applications or websites is required, with complete verification of the identities of parties requesting security measures.
Experts also stressed the necessity of rejecting any authentication notification that appears on smartphones if the user has not initiated the login request himself, with the importance of periodically reviewing the authentication methods associated with the account as soon as any unusual activity is detected.