Microsoft 365 Under Attack! How Hackers Are Using Vishing to Steal Your Passkeys (2026)

The world of cybersecurity is a complex and ever-evolving landscape, and the latest threat to emerge is a sophisticated vishing campaign targeting Microsoft 365's passkey enrollment process. This attack, orchestrated by the cyber extortion group Pink, highlights the evolving tactics of cybercriminals and the need for organizations to stay vigilant.

What makes this campaign particularly insidious is its ability to mimic legitimate processes, using a panel-controlled phishing kit that impersonates Microsoft Entra ID login pages in real-time. The hackers are clever in their approach, registering domains that incorporate the word 'passkey' and using voice-enabled phishing (vishing) to target users. By calling users on the phone and pretending to be Microsoft, they can persuade victims to register a new passkey, all while simultaneously registering their own passkey in the victim's account.

The success of this attack is further bolstered by the fact that it closely mimics Microsoft's own recent passkey registration activities, which began reminding users to enrol passkeys at sign-in. This well-intentioned security upgrade has inadvertently become a pretext for abuse, as threat actors exploit the enrollment process to further their objectives.

The hackers, as stated on their darknet leak site, are financially motivated. They claim that security is an expensive undertaking, especially when neglected, and their sole goal is profit. They understand the value of data and expect to extract value from it. This financial incentive drives their actions, and it's a stark reminder of the potential consequences of successful cyberattacks.

The targeted sectors in this campaign are diverse, including food and beverage, technology, healthcare, automotive, construction, and aviation. This broad range of industries highlights the pervasive nature of the threat and the need for comprehensive security measures across all sectors.

The domains used by the hackers to create their targeted subdomains are: assignpasskey[.]com, deploypasskey[.]com, passkeydeploy[.]com, passkeyadd[.]com, and setpasskey[.]com. These subdomains are designed to mimic the legitimate Microsoft passkey enrollment process, making it even more challenging for users to distinguish between the real and the fake.

In conclusion, this vishing campaign targeting Microsoft 365's passkey enrollment process is a stark reminder of the evolving tactics of cybercriminals and the need for organizations to stay vigilant. As the threat landscape continues to evolve, it is crucial to adopt comprehensive security measures and educate users on the latest phishing techniques to mitigate the risk of successful attacks.

Microsoft 365 Under Attack! How Hackers Are Using Vishing to Steal Your Passkeys (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Nathanial Hackett

Last Updated:

Views: 5544

Rating: 4.1 / 5 (52 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Nathanial Hackett

Birthday: 1997-10-09

Address: Apt. 935 264 Abshire Canyon, South Nerissachester, NM 01800

Phone: +9752624861224

Job: Forward Technology Assistant

Hobby: Listening to music, Shopping, Vacation, Baton twirling, Flower arranging, Blacksmithing, Do it yourself

Introduction: My name is Nathanial Hackett, I am a lovely, curious, smiling, lively, thoughtful, courageous, lively person who loves writing and wants to share my knowledge and understanding with you.