Find notable cyber news and cases, enriched with sources, timelines, and signals.

Pink new extortion brand within The Com

Threat Actor Meta
First reported
Last updated
Happening score
H score 31
2 unique sources, 2 articles

Summary

Hide ▲

Pink is a The Com-linked extortion brand associated with O-UNC-066 that is now being used in a voice-based phishing campaign against Microsoft 365 users. The activity sends targets to a panel-controlled phishing kit that mimics Entra passkey enrollment and captures credentials and MFA responses so the attacker can register an unauthorized passkey and gain account access. Okta says the campaign has targeted food and beverage, technology, healthcare, automotive, construction, and aviation organizations, and the brand is linked to a data leak site operating since April 2026 under the name Pink.

Related Happenings

ShinyHunters social engineering campaign targeting employee SSO accounts

Campaign
H score79 First: 17.07.2026 23:45 Last: 17.07.2026 23:45 Sources 1

About this happening: The ShinyHunters extortion gang is running an ongoing social engineering campaign against employee Microsoft Entra, Okta, and Google SSO accounts, creating a path into...

Helix vishing and SharePoint data-extortion campaign

Campaign
H score38 First: 09.07.2026 20:08 Last: 09.07.2026 20:08 Sources 1

About this happening: The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...

Forg365-ForgCookie alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score37 First: 09.07.2026 17:39 Last: 09.07.2026 17:39 Sources 1

About this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...

O-UNC-066 / Pink Microsoft Entra passkey vishing campaign

Campaign
H score37 First: 08.07.2026 19:47 Last: 08.07.2026 19:47 Sources 1

How related: The campaign has been running since April and involves calling targeted users and trying to convince them to register a new passkey under the attacker's control.

About this happening: The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...

Vidar-XMRig malvertising campaign targeting consumers and SMBs worldwide

Campaign
H score31 First: 08.07.2026 14:00 Last: 08.07.2026 14:00 Sources 1

About this happening: A malvertising campaign is targeting consumers and small and medium businesses worldwide with archives that deploy Vidar and XMRig, creating both theft and cryptom...

Timeline

  1. 08.07.2026 19:47 1 articles · 14d ago

    Pink launches extortion site to publish stolen data samples

    Campaign Scope Update

    The Pink extortion group launched an extortion site on May 31 to publish samples of stolen data and pressure compromised victims into paying a ransom.

    Show sources
  2. 08.07.2026 19:47 3 articles · 14d ago

    Okta attributes Microsoft Entra passkey vishing to O-UNC-066 and Pink

    Initial Disclosure

    Okta attributes a Microsoft 365 vishing campaign to O-UNC-066, an actor it links to Pink and The Com, saying targeted employees across food and beverage, technology, healthcare, automotive, construction, and aviation sectors are called with fake security requests to enroll a Microsoft Entra passkey under attacker control. The phishing flow uses branded pages that mimic the real Entra passkey enrollment portal and an operator-controlled PHP panel that relays credentials and MFA responses in real time.

    Show sources