Vishing actors target Entra passkey enrollment
Contributor:
Houssem Eddine Bordjiba
05 July 2026 Time to read: ~
Topics
Social Engineering, Threat Intelligence, Phishing, IAM
Table of Contents
Share
Ready to make Identity a business advantage?
Get startedExecutive Summary
Since April 2026, a threat actor tracked as O-UNC-066 has deployed a panel-controlled phishing kit targeting the passkey enrollment process for Microsoft 365 customers.
The threat actor calls targeted users and persuades them that they need to register a new passkey. Users are directed to a phishing kit that closely mimics the Microsoft passkey enrollment process.
Infrastructure
Threat actors were observed creating subdomains for targeted entities under the following domains:
assignpasskey[.]comdeploypasskey[.]compasskeydeploy[.]com
Recommendations
Enroll users in strong authenticators such as Okta FastPass, passkeys or smart cards and enforce phishing resistance in policy.
| Tactic | Control |
|---|---|
| Phishing | Use phishing-resistant authentication |
| Valid Accounts | Restrict access by network and device context |