Identity · 63 days ago
Attackers are no longer just stealing logins here. They are using the passkey enrollment flow itself as the takeover mechanism, so the victim thinks they are adding a Microsoft passkey while the attacker registers their own to the same account in real time.
Okta says O-UNC-066, also tracked as CL-CRI-1147 and Pink, is using voice-based phishing and an operator-controlled kit against Microsoft 365 users across technology, healthcare, manufacturing, transportation, and other sectors. The panel adapts during the session to whatever MFA is enabled, including TOTP, push with number matching, and SMS OTP, and the end result is unauthorized access for data extortion.
That makes passkey rollout and helpdesk-style identity verification a live attack surface, not just a safer replacement for passwords. Any registration workflow that trusts the person on the phone can be turned into a durable account-takeover path.
7 sources covering this story
Starting September 1, 2026, passkeys will become the default authentication experience in Microsoft Entra.
Hackers find a new trick to collect Microsoft Entra user data without raising red flags
Organizations should check their logs for signs of an increasingly popular obfuscation technique, Proofpoint said.
Hackers find a new trick to collect Microsoft Entra user data without raising red flags
Organizations should check their logs for signs of an increasingly popular obfuscation technique, Proofpoint said.
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
O-UNC-066 uses vishing and a live phishing kit to trick Microsoft 365 users into enrolling attacker-controlled Entra passkeys for account access.
Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
The attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages.
Extortion crew hijacks Microsoft 365 accounts via fake passkey setup - Help Net Security
A cyber extortion crew is tricking employees into giving them access to Microsoft 365 accounts by faking Entra passkey enrollment requests.
Entra passkey enrollment vishing targets Microsoft 365 users
A threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra passkey.
Part of the PlainSec briefing for 2026-07-13