Criminals Are Calling Your Staff and Stealing Microsoft 365 Logins in Real Time

A hacking group is phoning employees, sending them to fake Microsoft Entra ID login pages, and quietly registering their own passkeys before anyone notices. Okta has the details.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a modern office desk with a smartphone lying face-up showing an incoming call
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • A criminal group tracked by Okta as O-UNC-066, also known as Pink, has run a phone-based fraud campaign targeting Microsoft 365 accounts since at least April 2025.
  • The group has hit organisations in automotive, aviation, construction, healthcare, and technology sectors, among others.
  • Attackers guide victims through a fake Microsoft Entra ID login process in near-real time, watching each step and updating what appears on screen.
  • The goal is data extortion: steal files, then demand payment to keep them private.
  • Victims receive a genuine Microsoft notification email after the attack, which is the clearest early warning sign.

A criminal group is cold-calling employees, pretending to help them set up a new security feature, and walking away with permanent access to their Microsoft 365 accounts. Okta, the identity security company, published details of the campaign this week.

The scam starts with a voice call. Vishing (voice phishing) is where a caller pretends to be from IT support or a trusted vendor to trick someone into handing over account details. The caller tells the target they need to register a passkey, a newer password-free login method. That sounds routine enough.

How does the fake login page fool people?

Victims land on a page that mirrors Microsoft's own Entra ID login, using legitimate branding and images loaded directly from Microsoft's content delivery network. It's built fresh for each target from the kit's back end.

Most phishing sites just hoover up whatever you type and store it. This one's different. A live operator sits behind a PHP control panel, watching in real time. As the victim types their password, the criminal immediately enters it into the real Microsoft site. They see which security check Microsoft then requests, whether that's a text code or an authenticator push notification, and update the fake page to ask the victim for the same thing.

The victim thinks they're enrolling a new passkey. They're actually handing the criminal a live session inside their account.

Once in, the criminal registers their own passkey tied to their own device. From that point they can log back in any time, even after the victim changes their password.

Microsoft does send a genuine confirmation email when a new passkey is registered. That email is the canary. Any employee who receives one they didn't request should call IT immediately and revoke access.

The group has also been using a distraction step involving BIP-39 recovery phrases, the word-list standard borrowed from cryptocurrency wallets. Okta says these phrases have no direct role in Microsoft Entra; they're likely there to keep the victim occupied while the real account takeover completes in the background.

We covered the Pink crew's earlier activity on 8 July, and a separate extortion group running almost identical phone tactics turned up the following day. This pattern isn't slowing down.

For ordinary employees, the advice is short: no IT team will call you out of the blue and ask you to log in to anything during the call. Hang up, find your helpdesk number yourself, and report it.

Operational takeaway: If your Microsoft tenant isn't configured to alert security teams the moment a new passkey or authenticator is registered on any account, fix that before next Monday.

© 2026 Threat Vectr