Vishing actors target Entra passkey enrollment
ID: 998dc200-fb36-5c8a-b461-e7948952203e
STIX ID: report--998dc200-fb36-5c8a-b461-e7948952203e
Feed Name: Okta Threat Intelligence
Since April 2026, the O-UNC-066 (Pink) threat actor has conducted a vishing-enabled phishing campaign that targets Microsoft 365 passkey enrollment: attackers call targeted users, direct them to passkey-themed domains and a phishing kit that mimics Microsoft’s enrollment flow, and attempt to register attacker-controlled passkeys in victims’ accounts. Okta observed targeting across multiple industries (food & beverage, technology, healthcare, automotive, construction, aviation) with a data-extortion motive; the phishing kit does not handle third-party federation and Okta has not observed direct Microsoft account compromises in this report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
