**Threat Actor Exploits Microsoft Entra Passkey Feature to Phish Users**
A sophisticated threat actor has been targeting organizations across various sectors with a clever voice phishing scam, convincing victims to enroll a new Entra passkey under their control. The attackers are taking advantage of a recent security feature introduced by Microsoft in May, which allows administrators to run passkey registration campaigns to encourage users to adopt more secure authentication methods.
The campaign, which began in April, involves phone calls to targeted users, claiming that they need to enroll a new Entra passkey for security reasons. The attackers then direct victims to phishing websites that mimic the legitimate Microsoft passkey enrollment process, complete with branding and logos from the victim’s organization. Unbeknownst to the victims, these sites are actually controlled by the attacker, who guides them through the phishing process in real-time using a PHP panel.
As users attempt to enroll their new passkeys, they are prompted to enter their credentials and multi-factor authentication (MFA) responses on the phishing site’s screens. The attacker then uses this information to authenticate to the victim’s Microsoft account, effectively registering a passkey under their control while the user believes they are completing a legitimate action.
Okta, a cloud-based identity and access management company, attributes this activity to an actor known as O-UNC-066, which operates under the extortion brand “Pink.” Pink is affiliated with The Com, a decentralized threat network that uses vishing and IT impersonation to collect credentials and MFA codes. After gaining access to a victim’s account, Pink moves quickly to exfiltrate data from SharePoint and OneDrive services.
The use of Entra passkeys in this scam highlights the importance of educating users about new security features and processes. While Microsoft’s introduction of passkey registration campaigns was intended to promote more secure authentication methods, it has instead been exploited by attackers to phish users.
To mitigate this threat, organizations should establish robust verification procedures for helpdesk personnel when contacting users and deny requests from locations where services are not offered. Additionally, security teams must stay vigilant and regularly test their defenses through breach and attack simulation exercises to identify vulnerabilities before they can be exploited by attackers.
In a recent report, researchers noted that 54% of successful attacks go undetected, highlighting the need for organizations to prioritize proactive security measures over reactive incident response. By staying ahead of threats and educating users about new security features, organizations can reduce their risk exposure and protect themselves against sophisticated phishing campaigns like this one.
Source: Bleeping Computer — 2026-07-08