Vishing actors target Entra passkey enrollment
ID: 929c2b51-003e-563f-9931-59c4523eb27f
STIX ID: report--929c2b51-003e-563f-9931-59c4523eb27f
Feed Name: Threat Intelligence | Blog | Okta
Since April 2026, Okta observed a campaign by O-UNC-066 (aka Pink) that combines voice phishing (vishing) and a panel-controlled phishing kit which closely mimics Microsoft 365 passkey enrollment; victims are called and directed to fraudulent sites where attackers attempt to register their own passkey in the victim’s account to enable account takeover and data extortion. Targets include enterprises across food & beverage, technology, healthcare, automotive, construction, and aviation; Okta notes the kit does not handle third-party federation (e.g., Okta) and they have not directly observed Microsoft account compromises, but have published guidance on reducing phishing risk in authenticator enrollment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
