GoFirm
Back to Blog
Case Studies·4 min read

The passkey enrolment tool Microsoft built to stop phishing became the phishing lure itself.

By GoFirm

In May 2026, Microsoft opened a new capability to enterprise administrators: passkey registration campaigns, an initiative to push employees away from passwords and toward hardware-bound Microsoft Entra passkeys.

By April, before the feature had even fully rolled out, a threat actor calling itself Pink, tracked by identity security vendor Okta under the designation O-UNC-066, had already built an attack around it. Pink's operators dial employees directly, claim to be internal IT support, and tell the target that a new Entra passkey must be enrolled immediately for security reasons. The call ends with a link. The link opens a page carrying the victim organisation's own branding and the word "passkey" in its domain name, built to look exactly like the enrolment portal Microsoft had just introduced.

The phishing kit behind the call is not the usual static adversary-in-the-middle proxy. Okta's technical analysis, published 6 July 2026, describes an operator-controlled PHP panel that steers each victim through the fake enrolment process in close to real time, polling the session every second to keep pace with what the target is doing on screen. As the employee enters their username, password, and whatever multi-factor response their organisation requires, whether a time-based code, a push notification with number matching, or an SMS one-time passcode, the kit relays each value to the operator, who uses it immediately to authenticate to the real Microsoft 365 account.

While the victim believes they are registering their own new passkey, the operator is registering one they control instead. To hold the employee's attention through the final steps, the kit displays a fake BIP-39 recovery phrase and asks the victim to confirm a word from it, a cryptocurrency wallet convention that has no role whatsoever in genuine Entra passkey enrolment. It exists only to look official long enough for the attacker to finish taking over the account.

Okta has tracked Pink's calls into organisations across food and beverage, technology, healthcare, automotive, construction, and aviation since April 2026. Palo Alto Networks' Unit 42 identified phishing domains carrying the word "passkey" as far back as early June. Pink, an extortion brand affiliated with the loose criminal network known as The Com, opened its own dark web leak site on 31 May 2026, where it posts samples of stolen SharePoint and OneDrive data and gives victims a 72-hour deadline before more is published. It is the third major vishing brand tied to The Com's affiliates to build a working extortion operation around a single phone call in 2026, following the ShinyHunters campaigns against Salesforce customers and the Silent Ransom Group's law firm intrusions.

The defences that failed here were not weak by conventional standards. Passkeys are phishing-resistant by design, and enrolling one is precisely the security upgrade organisations have been told to pursue. Microsoft's own enrolment campaign feature, multi-factor authentication, and security awareness training were all present and all functioning exactly as intended. None of them were built to ask a second question: is the person calling to demand this enrolment actually authorised to request it, and is the device being registered actually the employee's own.

Passkey enrolment is an execution event. It permanently binds a new credential to an account, and once Pink's operator registers their own device, the legitimate user's access is no longer the only access that exists. Before that binding can complete, GoFirm sends a real-time push notification to the named account holder's own registered device, requiring biometric confirmation on a channel entirely separate from the phone call and the browser session the attacker is manipulating.

An operator running a live PHP panel can adapt to a one-time code or a push prompt typed into their fake page. What they cannot do is produce a fingerprint or face scan on a device they have never held, delivered through a channel their phishing kit was never built to see. The vishing call, however convincing the caller and however official the fake portal looks, cannot produce that confirmation. The execution boundary holds regardless of how credible the impersonation appears.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence.
Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. Toulas, B. 2026. Entra passkey enrollment vishing targets Microsoft 365 users. BleepingComputer, 8 July 2026.
2. Okta Threat Intelligence. 2026. Vishing actors target Microsoft Entra passkey enrollment. Okta, 6 July 2026.
3. Duncan, B. 2026. Pink extortion brand activity: phishing domain tracking. Unit 42, Palo Alto Networks, 3 June 2026.

Share this article