Tendvane

← All articles

AccountsSeptember 8, 2026

This phishing kit switches off your security key, then asks for a code instead

Researchers at CloudSEK did something unusual on this one: they got administrator access to the criminals' own control panel. What they published on 7 September is therefore a headcount rather than an estimate. The panel held 5,137 records taken from 461 targeted organisations, including 1,032 passwords in plain text, 4,148 session cookies and 474 sign-ins where two-factor authentication was defeated end to end. Victim addresses came from more than 40 countries. The service runs on rented servers and is leased out to at least five separate operators, which is what "phishing as a service" means in practice.

The mechanics are worth understanding once, because they explain why a text code is no longer much of a wall. You click a link and land on what looks like the Microsoft 365 sign-in page. It is actually a proxy sitting in the middle, passing your keystrokes to the real Microsoft and passing Microsoft's replies back to you. You type the password. You approve the prompt on your phone. Microsoft, seeing a legitimate sign-in, issues a session cookie. The proxy grabs that cookie before your browser ever gets it, and the attacker loads it in their own browser and is simply inside your mailbox. No password needed again, no second prompt.

Then the detail that makes this one newsworthy. The kit injects JavaScript that tells your browser it has no security key, by setting PublicKeyCredential to undefined and refusing passkey requests. So the passkey or hardware key you set up never appears as an option, and the page politely offers you a code instead. That is deliberate: a FIDO2 passkey is the one form of two-factor this attack cannot get around, so the kit hides it and herds you toward the version it can steal.

Practical upshot: if a Microsoft sign-in page suddenly does not offer your passkey and wants a code, treat that as the alarm rather than an annoying glitch. Reach sign-in pages by typing the address yourself, not from a link in a message. Tendvane's Privacy and accounts check shows which accounts your PC is signed into and how each one is protected, which is the list you want in front of you before deciding where a passkey matters most.

Sources

Download Tendvane