Cyber Security Published on July 8, 2026
Pink threat group abuses Microsoft Entra passkey enrollment in vishing attacks
Okta tracks the threat actor as O-UNC-066, operating the Pink extortion brand.
Since April 2026, the group has called targets pretending to be IT helpdesk staff and convinced them to enroll a new Entra passkey.
Victims are directed to an operator-controlled PHP phishing kit that mimics the legitimate Microsoft passkey enrollment flow, relays credentials and MFA responses in real time, and ultimately registers a passkey controlled by the attacker. After compromise, the group exfiltrates data from SharePoint and OneDrive.
Source: BleepingComputer