Identità · 77 giorni fa
Microsoft Entra passkey enrollment non è più solo il bersaglio da imitare: diventa il punto in cui l’attaccante si inserisce e registra la propria chiave sull’account della vittima. La difesa classica contro il phishing, centrata su credenziali rubate o token intercettati, perde efficacia quando il furto passa da un percorso di enrollment legittimo e lascia dietro un metodo di accesso duraturo.
Okta attribuisce la campagna a O-UNC-066, detto anche CL-CRI-1147 e Pink, e descrive un panel operator-controlled che guida la vittima in tempo quasi reale attraverso pagine che imitano il flusso Microsoft. Il kit adatta la schermata alle MFA presenti — TOTP, push con number matching, SMS OTP — mentre l’attaccante usa il momento della sessione per far registrare il proprio passkey sull’account; il targeting osservato tocca tecnologia, healthcare, manufacturing, trasporti, automotive, construction, aviation, food and beverage.
Per i team Entra e Microsoft 365 il punto non è solo bloccare una finta login page. Se il flusso di registrazione o la verifica telefonica viene controllato dall’esterno, l’approvazione stessa può diventare la chiave di accesso, e il takeover resta valido anche dopo la fine della chiamata.
7 fonti che coprono questa storia
Starting September 1, 2026, passkeys will become the default authentication experience in Microsoft Entra.
Hackers find a new trick to collect Microsoft Entra user data without raising red flags
Organizations should check their logs for signs of an increasingly popular obfuscation technique, Proofpoint said.
Hackers find a new trick to collect Microsoft Entra user data without raising red flags
Organizations should check their logs for signs of an increasingly popular obfuscation technique, Proofpoint said.
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
O-UNC-066 uses vishing and a live phishing kit to trick Microsoft 365 users into enrolling attacker-controlled Entra passkeys for account access.
Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
The attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages.
Extortion crew hijacks Microsoft 365 accounts via fake passkey setup - Help Net Security
A cyber extortion crew is tricking employees into giving them access to Microsoft 365 accounts by faking Entra passkey enrollment requests.
Entra passkey enrollment vishing targets Microsoft 365 users
A threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra passkey.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-07-13