Microsoft Users Relying on Passwords Instead of Passkeys are Direct Targets for Hackers

Microsoft has issued a stern warning to its over one billion users: remove your passwords and switch entirely to passkeys. According to the company, if a password remains on your account, that account is at high risk of attack and can be easily hijacked.Much like Apple and Google credentials, Microsoft account details are considered highly valuable to attackers because they provide access to numerous critical services.

Microsoft: The Most Impersonated Brand

Cybersecurity firm Check Point recently released a new warning stating, "In the first quarter of 2026, Microsoft remains the most impersonated brand in phishing attacks." Microsoft’s name is being used in 22% of all brand impersonation attempts. This result confirms a long-standing trend: attackers continuously exploit highly trusted brands to gain initial access to both personal and professional environments.

The Mechanics of the Attack

Check Point identified a specific malicious attack that mimics Microsoft’s legitimate authentication service to show users a fake login page. The URL used in these attacks is designed to deceive users into believing it is an authentic Microsoft site.

According to the report, attackers hide the brand name within a 'sub-domain' of an unrelated parent domain. The goal is to trick users who do not examine the full URL carefully.

If a user enters their email address on such a fake page, the 'authentication flow' sends a verification code, but then directs the user to a non-functional login screen. This entire process is designed solely to steal or harvest your email and password details.

How to Protect Yourself

If you encounter a suspicious Microsoft login page, exit immediately. If you have unknowingly entered your details, change your password without delay. Furthermore, if you haven't set up passkeys and non-SMS-based Multi-Factor Authentication (MFA) on your Microsoft or any other accounts, do so immediately.

Other Targeted Brands

Check Point’s data shows that other major brands are also in the crosshairs:

Apple: 2nd place (11%) – Attackers are increasingly focusing on Apple users due to links with payments, identity, and personal devices.

Google: 3rd place (9%)

Amazon: 4th place (7%)

These four brands alone account for nearly 50% of all phishing attempts seen in the last quarter. This highlights how attackers are heavily concentrated on a few globally recognized platforms.

Ultimately, if you remove passwords from your accounts and switch to passkeys, you will be safe from such phishing attacks. However, if your account still relies only on a username, password, and a simple SMS code, you are currently a direct target for attackers.

Share:

Post a Comment