Skip to content
Vishing Campaign Targets Microsoft 365 Passkey Enrollment Process

Vishing Campaign Targets Microsoft 365 Passkey Enrollment Process

First seen 8 Jul 2026, 17:25 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 9, 2026 at 14:42 UTC
  • •Threat actor O-UNC-066, known as 'Pink', is behind the vishing campaign targeting Microsoft 365 users.
  • •The campaign exploits a new Microsoft feature for passkey enrollment, launched in May 2026.
  • •Phishing sites mimic legitimate Microsoft processes, collecting user credentials and MFA responses.

Since April 2026, a threat actor identified as O-UNC-066, also known as 'Pink', has been executing a vishing campaign aimed at Microsoft 365 users. The campaign exploits a new passkey enrollment feature introduced by Microsoft in May 2026, targeting organizations in various sectors, including food and beverage, technology, and healthcare. Attackers call users, convincing them to register a new passkey, while directing them to a phishing site that mimics the legitimate Microsoft enrollment process. The phishing kit is designed to collect user credentials and MFA responses in real-time, allowing the attacker to gain unauthorized access to victims' accounts. Okta has observed this activity but has not confirmed any direct compromises of Microsoft accounts. The phishing URLs used in the campaign contain the word 'passkey' and are tailored to each victim's organization. The threat actor's ultimate goal appears to be data extortion.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 93d ago How this analysis works

Timeline

2026-04-01
Vishing campaign begins targeting Microsoft 365 users
O-UNC-066 starts calling users to convince them to enroll new passkeys under attacker control.
Okta
2026-05-01
Microsoft launches passkey registration campaigns
New feature allows administrators to nudge users to enroll in passkeys, exploited by threat actors.
BleepingComputer
2026-07-08
Okta and BleepingComputer report on vishing campaign
Both sources detail the methods and targets of the O-UNC-066 vishing campaign, highlighting its impact.
Okta

More articles in this cluster (13)

Following this threat?

Track O-unc-066 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed