Microsoft Entra Passkey Enrollment Abused in Operator-Controlled Vishing Campaign
ID: 1c92e29c-adb2-50b0-b4f4-04487899488e
STIX ID: report--1c92e29c-adb2-50b0-b4f4-04487899488e
Feed Name: GBHackers
A targeted vishing/phishing campaign (attributed to cluster O-UNC-066, aka "Pink") weaponizes spoofed Microsoft Entra passkey enrollment to socially engineer enterprise users into a fake passkey ceremony while operators use a real-time control panel to collect credentials and MFA codes, enroll attacker-controlled passkeys, and achieve account takeover; the actors later published a data leak site (May 31, 2026). Defenders are advised to treat unsolicited passkey enrollment calls as high-risk, enforce conditional access and managed-device passkey policies, disable in-session passkey enrollment where feasible, monitor unusual passkey registrations and naming patterns, and use targeted user education.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
