← All stories
● Covered by 3 sources · 4 reportsMedium impact

Microsoft 365 Users Targeted in Voice Phishing Campaign for Fake Entra Passkey Enrollment

🔄 Updated 79d ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Voice phishing targets Microsoft 365 users for fake Entra passkey enrollment.
  • O-UNC-066 group responsible for the phishing campaign since April.
  • Okta identifies industries like healthcare, aviation, and technology being targeted.
  • Campaign uses phishing kits that imitate Microsoft enrollment webpages.
  • Potential unauthorized access enables data extortion.

Overview

A phishing campaign utilizing voice calls is targeting Microsoft 365 users, convincing them to enroll in fake Entra passkeys. This allows attackers unauthorized access to accounts, primarily for data extortion purposes.

Campaign Details

First detected in April 2023, this campaign was attributed to the group O-UNC-066, by Okta. It impersonates the Microsoft passkey enrollment process using sophisticated phishing kits.

The threat actor uses a panel-controlled phishing kit and registers domains featuring the term 'passkey' to make the fake process appear legitimate.

Industries Affected

Numerous sectors are affected, including technology, healthcare, automotive, construction, food and beverage, and aviation. This broad targeting underscores the vulnerability within organizations adopting the new passkey system.

Security Implications

This attack reveals potential flaws in Microsoft's recent push for passkey adoption, highlighting risks associated with enrollment processes for identity and access management solutions. The use of realistic phishing sites poses significant threats to account security across industries.

Concluding Remarks

Organizations need to be aware of the deceptive methods used in this campaign and prioritize educating employees on authenticating communications and verifying enrollment requests. Maintaining robust protective measures is critical to preventing unauthorized access.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Threat actors are using OAuth client ID spoofing to validate stolen credentials in Microsoft Entra ID, without triggering alerts. This technique bypasses traditional sign-in telemetry, allowing attackers to enumerate accounts and gain unauthorized access to cloud services.

Okta has reported a vishing campaign targeting Microsoft 365 users to harvest credentials. The attacks, which began in April, involve fraudsters directing victims to fabricated Microsoft Entra ID login pages under the guise of passkey registration, primarily affecting various industries for data extortion.

A threat actor is using a voice phishing scheme to trick Microsoft 365 users into enrolling fake passkeys, allowing unauthorized access to their accounts. This tactic targets various industries and highlights a concerning vulnerability amid Microsoft's push for passkey adoption, potentially facilitating data extortion attacks.

A phishing campaign is targeting Microsoft 365 users through voice calls to enroll in fake Entra passkeys. The attacker disguises the attack using a phishing kit that mimics the Microsoft enrollment process, posing a significant risk to victims' accounts.