Vishing actors target Entra passkey enrollment
ID: 2643e622-4e52-5b04-8486-9f22775c8965
STIX ID: report--2643e622-4e52-5b04-8486-9f22775c8965
Feed Name: Okta Threat Intelligence
Since April 2026, threat actor O-UNC-066 ("Pink") has conducted a targeted vishing and phishing campaign that abuses Microsoft passkey enrollment workflows: callers persuade enterprise users to enroll a passkey via domains containing the word “passkey” and a phishing kit that mimics Microsoft’s enrollment process while the attacker registers their own passkey in the victim’s account. The campaign targets organizations across multiple industries for data extortion; defenders have not observed direct compromise of Microsoft accounts but the technique is actively used and poses a notable risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
