logo

Vishing actors target Entra passkey enrollment

ID: c8c6e3af-820f-5de6-9274-a952ba8b5b73

STIX ID: report--c8c6e3af-820f-5de6-9274-a952ba8b5b73

Feed Name: Okta Threat Intelligence

Threat Score
70/100

Date Published: 2026-07-05

Date Updated: 2026-08-05

...
...

Since April 2026, the threat actor O-UNC-066 ("Pink") has conducted a panel-controlled vishing and phishing campaign targeting Microsoft 365 passkey enrollment. The actor registers 'passkey'-themed domains, calls targeted enterprise users across multiple industries to coerce them into enrolling a passkey, and serves a phishing kit that imitates Microsoft's passkey enrollment while the attacker simultaneously registers a passkey on the victim's account; the primary motive is data extortion. Okta observed the activity and noted the kit does not handle third-party IdP federation and that no direct Microsoft account compromises have been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.