Vishing actors target Entra passkey enrollment
ID: c8c6e3af-820f-5de6-9274-a952ba8b5b73
STIX ID: report--c8c6e3af-820f-5de6-9274-a952ba8b5b73
Feed Name: Okta Threat Intelligence
Since April 2026, the threat actor O-UNC-066 ("Pink") has conducted a panel-controlled vishing and phishing campaign targeting Microsoft 365 passkey enrollment. The actor registers 'passkey'-themed domains, calls targeted enterprise users across multiple industries to coerce them into enrolling a passkey, and serves a phishing kit that imitates Microsoft's passkey enrollment while the attacker simultaneously registers a passkey on the victim's account; the primary motive is data extortion. Okta observed the activity and noted the kit does not handle third-party IdP federation and that no direct Microsoft account compromises have been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
