www.okta.com Vishing Campaign Targets Microsoft 365 Passkey Enrollment Process
Article Content
- •Threat actor O-UNC-066, known as 'Pink', is behind the vishing campaign targeting Microsoft 365 users.
- •The campaign exploits a new Microsoft feature for passkey enrollment, launched in May 2026.
- •Phishing sites mimic legitimate Microsoft processes, collecting user credentials and MFA responses.
Since April 2026, a threat actor identified as O-UNC-066, also known as 'Pink', has been executing a vishing campaign aimed at Microsoft 365 users. The campaign exploits a new passkey enrollment feature introduced by Microsoft in May 2026, targeting organizations in various sectors, including food and beverage, technology, and healthcare. Attackers call users, convincing them to register a new passkey, while directing them to a phishing site that mimics the legitimate Microsoft enrollment process. The phishing kit is designed to collect user credentials and MFA responses in real-time, allowing the attacker to gain unauthorized access to victims' accounts. Okta has observed this activity but has not confirmed any direct compromises of Microsoft accounts. The phishing URLs used in the campaign contain the word 'passkey' and are tailored to each victim's organization. The threat actor's ultimate goal appears to be data extortion.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (13)
Following this threat?
Track O-unc-066 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…