Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Meet the innovators under 35 shaping climate tech

    September 17, 2026

    Washington Won’t Be Regulating AI Anytime Soon

    September 17, 2026

    OpenAI Creates a New Framework to Disclose Bad AI Behavior

    September 17, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Meet the innovators under 35 shaping climate tech
    • Washington Won’t Be Regulating AI Anytime Soon
    • OpenAI Creates a New Framework to Disclose Bad AI Behavior
    • The Download: AI’s trillion-dollar gamble and OpenAI’s biology data bid
    • I Trained a Fly’s Brain to Generate WIRED Story Ideas
    • Building the materials foundation for AI
    • Physical AI Safety Under Attack From Silent Backdoors
    • Meet a mouse whose brain cortex is made up of human cells
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
    Cybersecurity

    Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 11, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Vishing
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Organizations across multiple sectors have been targeted in a vishing campaign aimed at harvesting Microsoft 365 credentials, Okta warns.

    The campaign started in April and has involved voice calls directing the victims to fake Microsoft Entra ID login pages under the pretense that they need to register a new passkey.

    Tracked as O-UNC-066 and also known as CL-CRI-1147 and Pink, the hacking group has been targeting automotive, aviation, construction, food and beverage, healthcare, and technology organizations, mainly for data extortion.

    As part of the observed attacks, the threat actor has been registering domains incorporating the word ‘passkey’, and has been directing victims to pages that closely mirror the Microsoft passkey enrollment process.

    “It appears engineered to convince a targeted user they are in the process of enrolling a passkey with Microsoft, while the threat actor simultaneously registers their own passkey in the targeted user’s Microsoft account,” Okta says.

    The fake Microsoft Entra ID login pages are customized for each victim from the backend of the phishing kit, using legitimate branding and loading content from Microsoft’s content delivery network.

    Advertisement. Scroll to continue reading.

    Unlike other phishing kits, this is an operator-controlled PHP panel that does not automatically collect credentials, multi-factor authentication (MFA) tokens, and session tokens.

    Instead, the threat actor directs the victim through multiple authentication stages in near-real time, adapting the page’s content and notifications during the session to accommodate various MFA requirements.

    “It is likely that the threat actor uses the kit to take over the user account and trick the user into approving an attacker-initiated registration of a passkey,” Okta notes.

    Throughout the various stages of the attack, the phishing pages perform anti-analysis checks, request a username without redirecting to a federated identity provider, and request a password that the operator likely uses in real-time to access the victim’s account.

    Next, the victim is shown a processing page while the operator likely authenticates to the account to observe the type of MFA that has been enabled and selects what to display to the victim: SMS OTP, TOTP, or push MFA.

    In line with the campaign’s lure, the attacker can then redirect the user to a passkey registration page, where they are asked to save a recovery key from a list of BIP-39 phrases the threat actor controls. Next, the victim is asked to verify the final word used in the seed phrase.

    “The phishing kit appears to prey on the lack of user familiarity with passkey authentication. In a real passkey registration ceremony, the user might expect a system dialog to register a passkey on their device. The passkey pages in this phishing kit appear to mimic this process without registering a passkey,” Okta notes.

    According to the company, BIP-39 seed phrases do not appear to have a direct applicability in Microsoft Entra, and the hacking group may be using this step as a distraction. At the same time, attacker-controlled passkeys are enrolled in the victim’s account.

    “Any time a user enrolls a passkey with Microsoft, the owner of the compromised account receives a legitimate Microsoft email to notify them that a new passkey has been registered in their account. During an attack, the passkey was actually enrolled by the threat actor directly with Microsoft, and the threat actor is in a position to name the passkey with something the targeted user would view as benign,” Okta explains.

    Related: Massive Password Spray Campaign Targeting Azure CLI

    Related: FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service

    Related: Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices

    Related: Over 500 Organizations Hit in Years-Long Phishing Campaign

    Attacks Customers Microsoft Okta targeting vishing warns
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Meet the innovators under 35 shaping climate tech
    • Washington Won’t Be Regulating AI Anytime Soon
    • OpenAI Creates a New Framework to Disclose Bad AI Behavior
    • The Download: AI’s trillion-dollar gamble and OpenAI’s biology data bid
    • I Trained a Fly’s Brain to Generate WIRED Story Ideas

    Meet the innovators under 35 shaping climate tech

    September 17, 2026

    Washington Won’t Be Regulating AI Anytime Soon

    September 17, 2026

    OpenAI Creates a New Framework to Disclose Bad AI Behavior

    September 17, 2026

    The Download: AI’s trillion-dollar gamble and OpenAI’s biology data bid

    September 16, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.