Social EngineeringBleeping Computer
8.0 — CRITICAL
Entra passkey enrollment vishing targets Microsoft 365 users
A threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra passkey. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A threat actor, tracked as O-UNC-066 by Okta, has been targeting Microsoft 365 users with voice-based fake security requests to enroll a new Entra passkey, using phishing kits that mimic the legitimate Microsoft process.
⚙️Technical Details
Affected Systems
Microsoft 365
Attack Vectors
Voice-based vishingPhishing kit with operator-controlled PHP panel
💥Impact Assessment
Severity: High
Who Is at Risk
Organizations in the food and beverage, technology, healthcare, automotive, construction, and aviation industries
🛡️Recommended Actions
1Establish methods to better verify the identity of helpdesk personnel when contacting users
2Deny requests from locations where the company does not offer services
3Monitor for suspicious phone calls and phishing attempts
📦Affected Products
Microsoft 365
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
