Microsoftdescribes this attack, which has been observed since May 2026, as one that starts with identity-focused social engineering. “The threat actors call or message a user’s personal phone number, while claiming to be from the organization’s IT help desk and urging them to immediately update their passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration…