Entra passkey enrollment vishing targets Microsoft 365 users
An extortion crew tracked as Pink phones employees claiming they must enroll a new Entra passkey, then walks them through a relay panel that registers the attacker's passkey instead. The result is durable authenticated access to Microsoft 365.
A threat actor that Okta tracks as O-UNC-066, and Unit 42 as CL-CRI-1147, has been calling employees to say they must enroll a new Microsoft Entra passkey. The cluster sits inside The Com, the collective that also contains Scattered Spider, ShinyHunters, and LAPSUS$, and runs a leak site branded Pink. Victims are sent to phishing domains with "passkey" in the name imitating Microsoft's enrollment flow.
Behind it sits an operator-controlled PHP panel driving the session live. It adapts to whatever second factor the victim uses, TOTP, push, or SMS code, relaying what they supply to the operator, who authenticates against the real account. The victim believes they are registering their own passkey. In fact the attacker's is registered, with a recovery-key step used as misdirection, after which SharePoint and OneDrive are drained for extortion. Targets span food and beverage, technology, healthcare, automotive, construction, and aviation.
Why it matters
Researchers attribute the campaign's success largely to unfamiliarity. Users have been told passkeys are the secure option, and few have enrolled one often enough to recognise what a legitimate registration looks like.
This is not a weakness in WebAuthn. The cryptography did exactly what it promises: a passkey was bound to a real account. The failure was in enrollment, and it produces something worse than stolen credentials, because the attacker now holds a legitimate registered authenticator that survives a password reset.
The lesson is that phishing-resistant MFA protects authentication, not registration, and any programme that hardens the first while leaving the second reachable by a phone call has moved the attack rather than stopped it. Treat enrollment and recovery as the privileged operations they are: verify identity out of band before a helpdesk assists with either, block authentication from regions you do not operate in, and tell users plainly that unsolicited passkey enrollment requests are a known attack. Our enterprise passkey guide covers the enrollment controls this bypasses.
Source: BleepingComputer
Related on Start with Identity
- BlogConsentFix: hijacking Microsoft 365 through the OAuth consent flow
ConsentFix adapts the ClickFix pattern to identity. Instead of running a command on the victim's machine, it walks them through an OAuth consent flow and asks t
- BlogKali365 phishes Microsoft's own device login page for durable Microsoft 365 tokens
ANY.RUN documented Kali365, a kit that lures victims through fake SharePoint, OneDrive, and DocuSign pages to Microsoft's genuine device login portal, where app
- BlogAbbott investigates two incidents, one starting with a vished Entra account
Abbott confirmed unauthorized access to legacy Exact Sciences systems after a mid-June vishing attack compromised a Microsoft Entra single sign-on account. Shin
- GuideConditional Access Policies: A Complete Implementation Guide for Microsoft Entra
Master Microsoft Entra conditional access with risk-based policies, device compliance rules, location-based restrictions, and real-world deployment patterns.
- VendorMicrosoft Entra External ID
strong
- VendorMicrosoft Entra ID
top_tier