Passkey Enrollment Becomes the Account-Takeover Path
Attackers are no longer just stealing logins here. They are using the passkey enrollment flow itself as the takeover mechanism, so the victim thinks they are adding a Microsoft passkey while the attacker registers their own to the same account in real time.
Okta says O-UNC-066, also tracked as CL-CRI-1147 and Pink, is using voice-based phishing and an operator-controlled kit against Microsoft 365 users across technology, healthcare, manufacturing, transportation, and other sectors. The panel adapts during the session to whatever MFA is enabled, including TOTP, push with number matching, and SMS OTP, and the end result is unauthorized access for data extortion.
That makes passkey rollout and helpdesk-style identity verification a live attack surface, not just a safer replacement for passwords. Any registration workflow that trusts the person on the phone can be turned into a durable account-takeover path.