logo

Vishing actors target Entra passkey enrollment

ID: 998dc200-fb36-5c8a-b461-e7948952203e

STIX ID: report--998dc200-fb36-5c8a-b461-e7948952203e

Feed Name: Okta Threat Intelligence

Threat Score
68/100

Date Published: 2026-07-04

Date Updated: 2026-08-05

...
...

Since April 2026, the O-UNC-066 (Pink) threat actor has conducted a vishing-enabled phishing campaign that targets Microsoft 365 passkey enrollment: attackers call targeted users, direct them to passkey-themed domains and a phishing kit that mimics Microsoft’s enrollment flow, and attempt to register attacker-controlled passkeys in victims’ accounts. Okta observed targeting across multiple industries (food & beverage, technology, healthcare, automotive, construction, aviation) with a data-extortion motive; the phishing kit does not handle third-party federation and Okta has not observed direct Microsoft account compromises in this report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.