A phishing campaign utilizing voice calls is targeting Microsoft 365 users, convincing them to enroll in fake Entra passkeys. This allows attackers unauthorized access to accounts, primarily for data extortion purposes.
First detected in April 2023, this campaign was attributed to the group O-UNC-066, by Okta. It impersonates the Microsoft passkey enrollment process using sophisticated phishing kits.
The threat actor uses a panel-controlled phishing kit and registers domains featuring the term 'passkey' to make the fake process appear legitimate.
Numerous sectors are affected, including technology, healthcare, automotive, construction, food and beverage, and aviation. This broad targeting underscores the vulnerability within organizations adopting the new passkey system.
This attack reveals potential flaws in Microsoft's recent push for passkey adoption, highlighting risks associated with enrollment processes for identity and access management solutions. The use of realistic phishing sites poses significant threats to account security across industries.
Organizations need to be aware of the deceptive methods used in this campaign and prioritize educating employees on authenticating communications and verifying enrollment requests. Maintaining robust protective measures is critical to preventing unauthorized access.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Threat actors are using OAuth client ID spoofing to validate stolen credentials in Microsoft Entra ID, without triggering alerts. This technique bypasses traditional sign-in telemetry, allowing attackers to enumerate accounts and gain unauthorized access to cloud services.
Okta has reported a vishing campaign targeting Microsoft 365 users to harvest credentials. The attacks, which began in April, involve fraudsters directing victims to fabricated Microsoft Entra ID login pages under the guise of passkey registration, primarily affecting various industries for data extortion.
A threat actor is using a voice phishing scheme to trick Microsoft 365 users into enrolling fake passkeys, allowing unauthorized access to their accounts. This tactic targets various industries and highlights a concerning vulnerability amid Microsoft's push for passkey adoption, potentially facilitating data extortion attacks.
A phishing campaign is targeting Microsoft 365 users through voice calls to enroll in fake Entra passkeys. The attacker disguises the attack using a phishing kit that mimics the Microsoft enrollment process, posing a significant risk to victims' accounts.