Entra passkey enrollment vishing targets Microsoft 365 users

A sophisticated phishing campaign, dubbed “Pink,” has been targeting Microsoft 365 users across various industries, tricking them into enrolling fake Entra passkeys under the attacker’s control. The scheme exploits a legitimate Microsoft feature introduced in May, which allows administrators to run passkey registration campaigns. Threat actors are using this capability to phish victims and gain unauthorized access to their accounts.

The campaign, attributed to an actor tracked by Okta as O-UNC-066, has been ongoing since April, with targets including organizations in the food and beverage, technology, healthcare, automotive, construction, and aviation sectors. The attackers contact victims via phone, posing as helpdesk personnel and claiming that they need to enroll a new Entra passkey for security reasons. Victims are then directed to phishing URLs that mimic the legitimate Microsoft passkey enrollment process.

The malicious websites include the victim organization’s branding and use a unique operator-controlled PHP panel to adapt the phishing flow based on the multi-factor authentication (MFA) method used by each victim. This allows the attacker to steer victims through various stages of authentication in real-time, using a 1-second heartbeat polling mechanism. Once credentials and MFA responses are entered by the victim, they are relayed to the operator, who uses them to authenticate to the victim’s Microsoft account.

The goal of this phishing campaign is not just to obtain unauthorized access to accounts but also to extort victims by publishing stolen data on a dedicated extortion site. After gaining access, the attackers quickly exfiltrate data from SharePoint and OneDrive services. Okta notes that BIP-39 seed phrases are used as a distraction in the phishing process, with no actual role in legitimate Microsoft Entra passkey enrollment.

This campaign highlights the importance of verifying the identity of helpdesk personnel when contacting users and denying requests from locations where the company does not offer services. It also underscores the need for organizations to implement robust security measures to prevent such attacks.

The rise of sophisticated phishing campaigns like Pink emphasizes the need for continuous security awareness and training among employees. As threat actors become more cunning, it’s essential for organizations to stay ahead of the curve by regularly updating their security protocols and testing them through breach and attack simulation exercises. By doing so, they can identify vulnerabilities before attackers do, reducing the risk of successful attacks.


Source: Bleeping Computer — 2026-07-08