Microsoft is tracking adversary-in-the-middle and device-code attacks since May 2026 where victims get a convincing "helpdesk" call about passkeys, SSO, or MFA. Once the caller tricks the user into registering attacker-controlled MFA methods, operators run Microsoft Graph recon and then steal files from SharePoint/OneDrive (sometimes Exchange) at a paced rate — often under 1,000 files/hour to stay quiet. Clusters sit in the Storm-3121 / Storm-3032 / ShinyHunters ecosystem. BleepingComputer amplified the write-up on 2026-09-11.

This is core Livermore SMB risk: everyone has a helpdesk culture, and "IT called about my MFA" still works. The defense stack is boring and effective — phishing-resistant MFA where you can, block unused device-code flows, alert on new MFA method registrations, watch Graph consent spikes, and flag unusual download bursts.

Train the sentence out loud: We will never call you to add a passkey or MFA method. Hang up and call the number on your invoice.