Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
ID: 7bd6009d-0cb4-5c2d-9eae-d08c0bd4d4e6
STIX ID: report--7bd6009d-0cb4-5c2d-9eae-d08c0bd4d4e6
Feed Name: The Hacker News
Okta warns of an active vishing campaign (actor O-UNC-066) targeting multiple industries where victims are socially engineered to follow a Microsoft-branded passkey enrollment phishing flow; an operator-controlled PHP panel harvests credentials and MFA responses in near real-time, registers attacker-controlled passkeys on compromised Microsoft 365 accounts, and facilitates account takeover and data extortion. The activity is linked to a public data leak site (Pink) and tracked by other firms as part of a decentralized cybercrime collective.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
