Imagine someone stealing your house keys by tricking you into thinking they’re from the locksmith, and then using those keys to get into your online bank account. That’s essentially what’s happening with a new type of attack Microsoft just warned us about.

Cybercriminals are sending out a massive number of fake emails, pretending to be your company's CEO, to trick people into giving up their online account access. Microsoft saw over a million of these scam emails in just a few days this past August. These aren't just any fake emails, though. They’re using a clever trick involving something called "passkeys" [a new, more secure way to log in that doesn't use passwords].

Here’s how it works: the attackers send emails that look like they're from a legitimate, trusted source, but they're actually coming from sneaky third-party email systems. These emails try to scare you into thinking your account is at risk and that you need to "update your passkey" or "verify your login." If you fall for it and click the link, you're taken to a fake website that looks exactly like a real Microsoft login page.

When you try to "update" your passkey on their fake site, you're actually giving the bad guys access to your real account. Once they have that access, they can get into your Microsoft cloud [online storage and services, like OneDrive or Teams] account. This means they can look at your files, emails, and other sensitive information, and even steal it.

This is a big deal because passkeys are supposed to be more secure than regular passwords, making it harder for attackers to get in even if they know your password. This new trick shows that even with better security tools, social engineering [tricking people into giving up information] remains a powerful weapon for cybercriminals. It also highlights that even big tech companies like Microsoft are constantly battling new, sophisticated attacks.

This situation isn't unique to Microsoft. We're seeing a broader trend where attackers are getting much better at mimicking official communications and exploiting new security features. Instead of just deleting suspicious emails, take an extra step: if an email asks you to update security details, don’t click any links. Instead, go directly to the official website for that service (like Microsoft.com) by typing it into your browser, then log in there to check for any alerts or updates.

Always be suspicious of unexpected emails asking you to click links to “update” or “verify” your accounts.