Vishing actors target Entra passkey enrollment

Contributor:

Houssem Eddine Bordjiba

05 July 2026 Time to read: ~

Topics

Social Engineering, Threat Intelligence, Phishing, IAM

Table of Contents

Share

LinkedInX

Ready to make Identity a business advantage?

Get started

Executive Summary

Since April 2026, a threat actor tracked as O-UNC-066 has deployed a panel-controlled phishing kit targeting the passkey enrollment process for Microsoft 365 customers.

The threat actor calls targeted users and persuades them that they need to register a new passkey. Users are directed to a phishing kit that closely mimics the Microsoft passkey enrollment process.

Infrastructure

Threat actors were observed creating subdomains for targeted entities under the following domains:

Recommendations

Enroll users in strong authenticators such as Okta FastPass, passkeys or smart cards and enforce phishing resistance in policy.

TacticControl
PhishingUse phishing-resistant authentication
Valid AccountsRestrict access by network and device context