logo

Vishing actors target Entra passkey enrollment

ID: 2643e622-4e52-5b04-8486-9f22775c8965

STIX ID: report--2643e622-4e52-5b04-8486-9f22775c8965

Feed Name: Okta Threat Intelligence

Threat Score
65/100

Date Published: 2026-07-05

Date Updated: 2026-08-04

...
...

Since April 2026, threat actor O-UNC-066 ("Pink") has conducted a targeted vishing and phishing campaign that abuses Microsoft passkey enrollment workflows: callers persuade enterprise users to enroll a passkey via domains containing the word “passkey” and a phishing kit that mimics Microsoft’s enrollment process while the attacker registers their own passkey in the victim’s account. The campaign targets organizations across multiple industries for data extortion; defenders have not observed direct compromise of Microsoft accounts but the technique is actively used and poses a notable risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.