Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers

Okta Warns of Sophisticated Vishing Campaign Targeting Microsoft 365 Customers

A highly targeted vishing campaign is underway, with hackers using social engineering tactics to trick Microsoft 365 users into divulging their login credentials. The attacks, which began in April, have been observed by Okta and are being tracked as O-UNC-066.

The hacking group behind the campaign, also known as CL-CRI-1147 or “Pink”, is targeting organizations across multiple sectors, including automotive, aviation, construction, food and beverage, healthcare, and technology. The main goal of the attackers appears to be data extortion, with the hackers seeking to gain access to sensitive information.

The vishing attacks work by directing victims to fake Microsoft Entra ID login pages under the pretense that they need to register a new passkey. These pages are customized for each victim using legitimate branding and load content from Microsoft’s content delivery network, making them almost indistinguishable from genuine login pages.

According to Okta, the threat actor uses an operator-controlled PHP panel that does not automatically collect credentials or multi-factor authentication (MFA) tokens. Instead, the attacker directs the victim through multiple authentication stages in near-real time, adapting the page’s content and notifications during the session to accommodate various MFA requirements.

The attackers’ tactics are designed to exploit user familiarity with passkey authentication. In a real passkey registration ceremony, users would expect a system dialog to register a passkey on their device. The phishing kit used by the hackers mimics this process without actually registering a passkey. The final step involves asking the victim to verify a recovery key from a list of BIP-39 phrases controlled by the threat actor.

Okta notes that BIP-39 seed phrases do not appear to have any direct applicability in Microsoft Entra, and the hackers may be using this step as a distraction. In reality, the attacker-controlled passkeys are enrolled in the victim’s account.

The impact of these attacks is significant, with Okta warning that any time a user enrolls a passkey with Microsoft, the owner of the compromised account receives a legitimate Microsoft email to notify them that a new passkey has been registered in their account. However, during an attack, the passkey was actually enrolled by the threat actor directly with Microsoft.

For users and organizations using Microsoft 365, this campaign serves as a stark reminder of the importance of security awareness and vigilance. It is essential for users to be cautious when interacting with login pages, especially those that request sensitive information or prompt them to enroll new passkeys. By being aware of these tactics, individuals can take steps to protect themselves from falling victim to similar attacks in the future.

To stay safe, it’s crucial to:

* Be wary of unsolicited calls or emails requesting sensitive information

* Verify login pages by checking for legitimate branding and content from trusted sources

* Avoid enrolling new passkeys without explicit confirmation from Microsoft

* Stay up-to-date with security patches and updates for Microsoft 365

By taking these precautions, users can significantly reduce the risk of falling victim to sophisticated vishing campaigns like the one described above.


Source: SecurityWeek — 2026-07-10