The call that wants you to "verify" your passkey right now
A call or text says your account needs an urgent security update — maybe a passkey, maybe your login settings. It sounds cautious and modern, almost like good advice. That is exactly why it works, and why security researchers are watching it spread.
In September 2026, Microsoft's security team and several independent researchers documented an active, organized campaign built entirely around this one trick. It has mostly hit company employees and business accounts so far — but the script behind it is one that reaches personal accounts and older adults just as easily, because it is the same old con wearing new, more technical-sounding clothes.
What researchers actually found
Microsoft's Security Blog, published September 9, 2026, described a pattern it had tracked since May: someone calls or texts a person's own phone, claiming to be from IT support, and says a passkey, multi-factor authentication (MFA), or single sign-on setting has to be updated immediately "to avoid disruption." Microsoft attributes much of this activity to two groups it tracks as Storm-3121 and Storm-3032 — tied to the ShinyHunters and Falcon extortion crews, among others — and notes something important: the caller usually has no real interest in passkeys at all. The passkey talk is just the hook. It is used to walk the victim toward one of two things: a fake sign-in page that steals a password and session token, or a prompt to read back a "device code" that, once repeated to the caller, hands over live access to the account.
Once inside, Microsoft found, the attacker's first move is often to quietly register a security method of their own — so they keep a way back in even after the original password is changed. BleepingComputer's reporting on the same campaign adds that the follow-up damage moves slowly and deliberately, often under 1,000 files or emails an hour, specifically to stay under the radar of automated alarms.
Why this matters beyond the office
To be direct about what is and is not yet documented: the campaigns making news this month were aimed at company help desks and business Microsoft 365 accounts, not personal Gmail, bank, or Apple accounts. We want to be honest about that rather than stretch the story. But the underlying mechanism is not new, and it is not limited to businesses. BleepingComputer's separate reporting on account-recovery fraud put the logic plainly: "Why steal a user's second factor if you can convince someone with the rights to manage it to replace it for you?" That is exactly the question this scam answers — whether the "someone with the rights" is a corporate help desk or an older adult on their own phone.
And the pretext lands on familiar ground. The FBI's 2025 Internet Crime Report found that Americans age 60 and older reported $7.7 billion in losses last year — about a 60 percent increase from 2024. A caller who says "we need to verify your account" is not a new idea to that audience. What is new is the specific mention of a passkey, security key, or MFA reset, dressed up to sound like something only a careful, security-minded person would take seriously.
Passkeys are not the problem
It would be easy to read all this and decide passkeys are risky. They are not — they are one of the strongest protections available today, and CISA and the FIDO Alliance (the standards body behind the technology) actively recommend phishing-resistant methods like passkeys as a default, not an extra. The scam here does not break the passkey itself. It talks a person into approving someone else's passkey or device during setup, or into resetting an account so the real passkey no longer matters. The fix is not to avoid passkeys — it is to only ever set one up yourself, directly inside the app or website, never through a link or instructions someone handed you over the phone.
What to do
- Never read a code aloud, tap "approve," or type a password because someone who contacted you asked you to. A real security prompt can always wait until you've called back on your own terms.
- Hang up and call back on the number you already trust — the back of your card, the company's own website, or a number you look up yourself. Never the number the caller gave you.
- Set up or check a passkey only inside the app or website itself, on a device you already trust — never by following a link from a text, email, or phone call.
- Watch for a cluster of "verify your account" or password-reset emails you did not request, especially across more than one account at once. One is routine; several close together is a warning sign.
- Check your account's own security page occasionally — Google, Microsoft, Apple, and most banks all show a list of signed-in devices or registered security keys. Remove anything you don't recognize.
- Agree on a family rule now: if anyone gets an unexpected call about a parent's or grandparent's account "security," they call a trusted family member before doing anything else — the same rule that already defeats the grandparent-emergency scam.
- Report it. File at reportfraud.ftc.gov or ic3.gov if a call, text, or email like this reached you or a loved one, even if no money changed hands.
Related reading
- Password-reset burst in the Scam Library — the exact pattern this scam produces, and how it's normally caught before anyone notices.
- Protecting an older parent from email and phone scams — the family conversation and settings to change this week.
- If you clicked, or already gave up a code — the first-hour steps that matter most.
The follow-up email is where we watch.
The call or text is only half of this con — a "verify your account," password-reset, or new-device email usually lands with it, before or after. Family Sentinel reads a mailbox's own security settings and forwarding rules for exactly these takeover signs and alerts your family fast — read-only by design, enforced by Google and Microsoft themselves, with a real Security Architect behind every serious flag. Your family can also set a personal verification phrase, so a scammer can never fake a warning from us.
Start your free month →Want the next threat before it reaches you?
Scam Watch goes out regularly — the newest scams and how to spot them, in plain English. Free.