{"id":577059,"date":"2026-07-09T15:15:27","date_gmt":"2026-07-09T15:15:27","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/577059\/"},"modified":"2026-07-09T15:15:27","modified_gmt":"2026-07-09T15:15:27","slug":"extortion-crew-hijacks-microsoft-365-accounts-via-fake-passkey-setup","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/577059\/","title":{"rendered":"Extortion crew hijacks Microsoft 365 accounts via fake passkey setup"},"content":{"rendered":"<p>The Pink cyber extortion crew is tricking employees into giving them access to their Microsoft 365 accounts by faking Entra passkey enrollment requests.<\/p>\n<p>The attack<\/p>\n<p>The attack starts with a vishing call to an employee. The caller poses as IT and says it\u2019s time to set up a passkey. Everything after that is theater, built to keep the victim occupied while the attacker finalizes everything.<\/p>\n<p>The attackers instruct the target to visit a subdomain that mimics the Microsoft Entra ID login page, which has been customized to look like it belongs to the victim\u2019s employer.<\/p>\n<p>The target is instructed to log in to their Microsoft 365 account, enter their second authentication factor, and set up a passkey.<\/p>\n<p>The specific pages with these input requests are served via a <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/01\/23\/okta-vishing-adaptable-phishing-kits\/\" target=\"_blank\" rel=\"nofollow noopener\">panel-controlled phishing kit<\/a>, allowing the attackers to customize the authentication flow presented to the targeted users.<\/p>\n<p>\u201cThe operator can use the kit to adapt the user experience to each victim\u2019s MFA requirements (TOTP, push notification with number matching, SMS OTP) during the session,\u201d the researchers noted.<\/p>\n<p>The kit shows loading screens between the separate phishing pages, giving the attackers time to use the entered credentials and authentication factors to log in to the targets\u2019 Microsoft 365 accounts.<\/p>\n<p>Once access is achieved, they serve the targets with a page asking them to set up a passkey. <\/p>\n<p>The next page shows a Microsoft-branded prompt with a list of <a href=\"https:\/\/river.com\/learn\/terms\/b\/bip-39\/\" target=\"_blank\" rel=\"nofollow noopener\">BIP-39 seed phrase words<\/a> (borrowed from cryptocurrency wallets), and tells the target to write them down:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/07\/fake-ms-passkey-enrolment.webp\" class=\"aligncenter\" alt=\"Microsoft 365 passkey enrollment\" title=\"The \" save=\"\" your=\"\" recovery=\"\" key=\"\" phishing=\"\" page=\"\" okta=\"\"\/><\/p>\n<p class=\"text-center\">The \u201cSave your recovery key\u201d phishing page (Source: Okta)<\/p>\n<p>Finally, they are instructed to enter one of them to \u201cconfirm\u201d their recovery key, and when they do, they are served a page that confirms that a passkey registration was successful.<\/p>\n<p>\u201cWe are not aware of any direct applicability of BIP-39 seed phrases to Microsoft Entra or its passkey registration process. An attacker that has already gained unauthorized access to a user account can create their own recovery codes using a process that does not require any input from the real account holder,\u201d Okta researchers noted.<\/p>\n<p>\u201cIt is likely that these passkey-themed pages are available to the phishing kit operator as a sleight of hand. It is a distraction to keep a user occupied on a task while the threat actor enrolls their own passkey in the legitimate Microsoft user account.\u201d<\/p>\n<p>Why passkeys make such a good lure<\/p>\n<p>Passkeys are a genuine security improvement: they are phishing-resistant and cryptographically bound to the site that issued them, which is exactly why an attacker would want to enroll one on a target\u2019s account.<\/p>\n<p>\u201cAs of May 2026, Microsoft administrators have been able to create passkey registration campaigns that remind or \u2018nudge\u2019 users to enrol in passkeys at sign-in, and in some circumstances these nudges are on by default,\u201d Okta researchers <a href=\"https:\/\/www.okta.com\/en-au\/blog\/threat-intelligence\/vishing-actors-target-microsoft-entra-passkey-enrollment-\/\" target=\"_blank\" rel=\"nofollow noopener\">explained<\/a>.<\/p>\n<p>With enrollment prompts now appearing unbidden in Entra ID tenants, and employees getting used to seeing them, they make the perfect pretext.<\/p>\n<p>Okta has observed this campaign targeting enterprises in the food and beverage, technology, healthcare, automotive, construction, and aviation industries, and says that the goal is data extortion.<\/p>\n<p>Palo Alto Networks researchers <a href=\"https:\/\/github.com\/PaloAltoNetworks\/Unit42-timely-threat-intel\/blob\/main\/2026-06-03-Pink-Extortion-Brand-Activity.txt\" target=\"_blank\" rel=\"nofollow noopener\">documented<\/a> the same campaign in early June 2026. They say that the after gaining access to the victim\u2019s account, the attackers exfiltrate data from platforms like SharePoint and OneDrive, then use the compromised account to send their initial extortion email and internal Teams messages.<\/p>\n<p>They also tied this campaign to the Pink data extortion group\/brand, which say is likely a threat actor affiliated with <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/02\/27\/europol-the-com-network-arrests\/\" rel=\"nofollow noopener\" target=\"_blank\">The Com<\/a>, a decentralized network of mostly English-speaking and mostly young cybercriminals who organize across Discord, Telegram, and gaming platforms.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/07\/devider.webp\"\/><\/p>\n<p><strong>Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. <a href=\"https:\/\/www.helpnetsecurity.com\/newsletter\/\" rel=\"nofollow noopener\" target=\"_blank\">Subscribe here!<\/a><\/strong><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/07\/devider.webp\"\/><\/p>\n","protected":false},"excerpt":{"rendered":"The Pink cyber extortion crew is tricking employees into giving them access to their Microsoft 365 accounts by&hellip;\n","protected":false},"author":2,"featured_media":577060,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[74],"tags":[245742,117409,18,245743,19,17,45259,79755,22135,245744,31775,82,245745],"class_list":["post-577059","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-account-hijacking","tag-data-theft","tag-eire","tag-extortion","tag-ie","tag-ireland","tag-microsoft-365","tag-okta","tag-palo-alto-networks","tag-passkeys","tag-social-engineering","tag-technology","tag-vishing"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ie\/116890680439112148","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/577059","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=577059"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/577059\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/577060"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=577059"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=577059"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=577059"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}