O-UNC-066 / Pink Microsoft Entra passkey vishing campaign
Campaign
Summary
Hide ▲
Show ▼
The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra passkey. The flow uses panel-controlled phishing kits and Microsoft-like pages to guide victims through login and passkey enrollment while the operator registers an attacker-controlled passkey for unauthorized access and data extortion. The activity spans food and beverage, technology, healthcare, automotive, construction, and aviation organizations. Okta links the campaign to a data leak site called Pink and says the abuse has been active since April 2026.
Related Happenings
Helix vishing and SharePoint data-extortion campaign
Campaign
H score38
First: 09.07.2026 20:08
Last: 09.07.2026 20:08
Sources 1
About this happening:
The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Helix vishing and SharePoint data-extortion campaign
CampaignAbout this happening: The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Pink new extortion brand within The Com
Threat Actor Meta
H score31
First: 08.07.2026 19:47
Last: 08.07.2026 19:47
Sources 1
How related:
According to Palo Alto Networks Unit 42, Pink is a new extortion brand affiliated with the decentralized threat network known as The Com (short for The Community).
About this happening:
Pink is a The Com-linked extortion brand associated with O-UNC-066 that is now being used in a voice-based phishing campaign against Microsoft 365 users. The a...
Pink new extortion brand within The Com
Threat Actor MetaHow related: According to Palo Alto Networks Unit 42, Pink is a new extortion brand affiliated with the decentralized threat network known as The Com (short for The Community).
About this happening: Pink is a The Com-linked extortion brand associated with O-UNC-066 that is now being used in a voice-based phishing campaign against Microsoft 365 users. The a...
Meta For Business Facebook Messenger fake-verification phishing campaign
Campaign
H score29
First: 07.07.2026 10:00
Last: 07.07.2026 10:00
Sources 1
About this happening:
A phishing campaign abused Facebook Messenger chatbots and fake verification lures to steal Meta For Business credentials and sensitive identity data, creating account...
Meta For Business Facebook Messenger fake-verification phishing campaign
CampaignAbout this happening: A phishing campaign abused Facebook Messenger chatbots and fake verification lures to steal Meta For Business credentials and sensitive identity data, creating account...
Willow raises $7M seed round for AI agent IAM platform
Industry Action
H score10
First: 04.06.2026 17:22
Last: 04.06.2026 17:22
Sources 1
About this happening:
Willow emerged from stealth with $7 million in seed funding, giving the startup new capital to scale an identity and access platform for enterprise AI agents. The comp...
Willow raises $7M seed round for AI agent IAM platform
Industry ActionAbout this happening: Willow emerged from stealth with $7 million in seed funding, giving the startup new capital to scale an identity and access platform for enterprise AI agents. The comp...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
Campaign
H score39
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
CampaignAbout this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
Timeline
-
08.07.2026 19:47 4 articles · 14d ago
O-UNC-066 / Pink Microsoft Entra passkey vishing campaign
Initial DisclosureSince April, the operation has relied on phone-based security lures and cloned Microsoft enrollment pages to convince users to add an attacker-controlled Entra passkey.
Show sources
- Entra passkey enrollment vishing targets Microsoft 365 users — www.bleepingcomputer.com — 08.07.2026 19:47
- Entra passkey enrollment vishing targets Microsoft 365 users — www.bleepingcomputer.com — 08.07.2026 19:47
- Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers — www.securityweek.com — 10.07.2026 14:06
- Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access — thehackernews.com — 10.07.2026 13:30