A threat actor tracked by Okta as O-UNC-066 and linked to the Pink extortion operation is targeting enterprise Microsoft 365 users with voice phishing calls that impersonate internal security staff and direct victims to enroll a new Microsoft Entra passkey. The campaign, active since April, uses domains containing the word "passkey" and phishing pages designed to closely mimic Microsoft’s legitimate Entra passkey enrollment flow, taking advantage of Microsoft’s newer passkey registration prompts and campaign features introduced for administrators.
Okta said the operation relies on an operator-controlled PHP phishing panel that relays credentials and MFA responses in real time and adapts to the victim’s authentication method, allowing the attacker to authenticate to the victim’s Microsoft account and register a passkey under the attacker’s control. Researchers said the compromises are followed by rapid data theft from SharePoint and OneDrive, with victims observed across the food and beverage, technology, healthcare, automotive, construction, and aviation sectors; Pink has also launched an extortion site to pressure organizations by publishing samples of stolen data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Okta disclosed that O-UNC-066 uses a panel-controlled phishing kit that mimics Microsoft Entra passkey enrollment, adapts in real time to victims' MFA methods such as SMS OTP, TOTP, and push approval, and uses domains containing the word 'passkey.' The attackers then distract victims with fake passkey and recovery-key steps while enrolling an attacker-controlled passkey on the compromised Microsoft 365 account.
Palo Alto Networks reported that after hijacking Microsoft 365 accounts, the attackers exfiltrate data from SharePoint and OneDrive and then send extortion messages from the compromised account using email and Microsoft Teams. The reporting further tied the fake passkey enrollment campaign to a data-extortion objective.
In May 2026, Microsoft introduced or enabled by default passkey registration nudges for administrators, a feature the vishing campaign appears to exploit by directing victims into fake enrollment flows. The attackers timed their activity around this legitimate passkey rollout.
Since April 2026, the threat actor tracked by Okta as O-UNC-066, also known as Pink, has targeted Microsoft 365 users with voice phishing calls and phishing pages that imitate Microsoft Entra passkey enrollment. The campaign targeted organizations across food and beverage, technology, healthcare, automotive, construction, and aviation sectors.
On 2026-05-31, researchers said the Pink extortion operation launched an extortion site used to pressure victims by publishing samples of stolen data. This tied the vishing activity to a broader extortion operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecysecurity.news
Open sourcescworld.com
Open sourcesecurityweek.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceokta.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.