CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

Fake Microsoft Entra Passkey Enrollment Used in Voice Phishing Attacks Targeting M365 Users

July 10, 2026

A sophisticated threat actor tracked as O-UNC-066 by Okta is targeting organizations across multiple sectors with a voice-based phishing (vishing) scheme that tricks Microsoft 365 users into enrolling a fake passkey, ultimately granting the attacker unauthorized access to their accounts. The campaign, active since at least April 2026, has impacted industries including food and beverage, technology, healthcare, automotive, construction, and aviation.

The attacker registers domains containing the word ‘passkey’ and calls victims, persuading them to register a new passkey under the guise of a security upgrade. Victims are directed to a phishing kit that mimics the legitimate Microsoft passkey enrollment process. Unlike typical adversary-in-the-middle (AitM) attacks, this kit is an operator-controlled PHP panel that allows real-time adaptation to each victim’s multi-factor authentication (MFA) requirements, such as TOTP, push notifications with number matching, or SMS OTP.

The attack chain begins with the victim entering their username and password on the phishing kit, which forwards the credentials to the operator. The operator then logs into the legitimate Microsoft sign-in page for the targeted tenant, triggering MFA challenges. The victim is prompted to provide the OTP or approve a push notification, which the operator captures and uses to complete authentication. Once access is obtained, the victim is guided through a fake passkey registration process, including a recovery key step with a 12-word seed phrase, which serves as a distraction while the attacker enrolls their own passkey.

Okta notes that the kit preys on user unfamiliarity with passkey authentication. Palo Alto Networks Unit 42 tracks this cluster as CL-CRI-1147 and links it to a decentralized cybercrime collective known as The Com, which includes groups like Scattered Spider, ShinyHunters, and LAPSUS$. The threat actor also operates a data leak site named Pink. No CVEs are associated with this campaign.

CVEs: CVE-2026-55200, CVE-2026-46817

Attack groups: O-UNC-066, CL-CRI-1147, The Com, Scattered Spider, ShinyHunters, LAPSUS$

Companies: Okta, Palo Alto Networks, Microsoft

Products: Microsoft Entra, Microsoft 365