Alex Yao Alex Yao
Back to news
Cyber Security Published on July 8, 2026

Pink threat group abuses Microsoft Entra passkey enrollment in vishing attacks

Okta tracks the threat actor as O-UNC-066, operating the Pink extortion brand.

Since April 2026, the group has called targets pretending to be IT helpdesk staff and convinced them to enroll a new Entra passkey.

Victims are directed to an operator-controlled PHP phishing kit that mimics the legitimate Microsoft passkey enrollment flow, relays credentials and MFA responses in real time, and ultimately registers a passkey controlled by the attacker. After compromise, the group exfiltrates data from SharePoint and OneDrive.