The bottom line: Threat actors O-UNC-066 use social engineering and a controlled phishing kit to gain access to Microsoft 365 accounts via Entra Passkey enrollment and subsequently conduct data extortion attacks.
A threat actor designated O-UNC-066 by Okta is targeting organizations across multiple sectors with voice phishing to trick Microsoft 365 users into registering an Entra Passkey. The goal is data extortion attacks.
The hacker group O-UNC-066, monitored by Okta, is currently conducting targeted attacks on organizations across multiple sectors. The attack method combines voice-based phishing – fraudulent calls – with technically manipulated enrollment processes. The goal of these attacks is to trick Microsoft 365 users into registering a new Entra Passkey on their accounts.
The attackers deploy a panel-controlled phishing kit specifically designed for the Passkey enrollment process. This automated system enables the actors to capture and control the credentials and authentication mechanisms of their targets. By gaining control of an account with a newly registered Passkey, the attackers secure persistent access to their victims’ Microsoft 365 environments.
Once the intruders gain administrative or extensive access privileges, they exfiltrate sensitive data from the affected organizations – particularly business and customer data. This is then used as the basis for data extortion attacks: the attackers threaten to publish or sell the data unless victims pay a ransom. The cross-sector nature of this campaign indicates an opportunistic approach in which O-UNC-066 deliberately seeks easily exploitable entry points.
Source: thehackernews.com · Published 10 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.