Skip to content

Attackers Hijack Passkey Registration via Voice Phishing at Microsoft 365

The bottom line: O-UNC-066 uses voice phishing combined with deceptively authentic phishing websites and manually controlled PHP panels to steal access from Microsoft 365 customers.

A hacker group named O-UNC-066 is using voice phishing to abuse passkey registration processes at Microsoft 365 customers. The attackers call employees, pose as IT support, and lure them to fake registration pages to steal login credentials and recovery keys.

Since April 2026, the hacker group O-UNC-066 (also called “Pink”) has been conducting an attack campaign against large enterprises in the food, technology, healthcare, automotive, construction, and aerospace sectors. The objectives are data theft and subsequent extortion. The attack target: the passkey registration processes of Microsoft 365 environments.

The attack flow exploits a psychological vulnerability: since May 2026, Microsoft has offered “Nudge” campaigns that prompt users at login to set up a passkey promptly. The attackers register domains with the word “Passkey” in the name and call potential victims directly. They pose as internal IT support and claim that urgent passkey registration is required. Many users have become accustomed to such requests through internal security initiatives and thus do not grow suspicious.


Source: www.it-daily.net · Published 15 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: