Pink Exploits Microsoft Entra Passkey: A Rising Threat in Cybersecurity
The Pink data extortion group, identified as O-UNC-066 by Okta and CL-CRI-1147 by Palo Alto’s Unit 42, has intensified its sophisticated voice phishing (“vishing”) campaign aimed squarely at corporate employees using Microsoft 365 and Entra ID environments. This aggressive campaign, which has been in operation since April 2026, has seen a notable increase in activities throughout July 2026. The group is specifically targeting critical sectors, including healthcare, technology, aviation, automotive, construction, and food and beverage industries.
Exploiting Vulnerabilities
The crux of Pink’s strategy revolves around the effective exploitation of user unfamiliarity with cryptographic passkeys. They have ingeniously synchronized their social engineering tactics with Microsoft’s rollout of automated passkey registration prompts in May 2026, capitalizing on the confusion it engendered among users. By masquerading as internal IT helpdesk personnel over the phone, Pink operators efficiently direct employees to carefully crafted, employer-branded lookalike subdomains. This clever impersonation leads employees into a false sense of security, allowing the hackers to connect to the legitimate accounts of their victims almost in real time. Utilizing a robust, operator-controlled backend panel, Pink can intercept login credentials while also dynamically altering the phishing interface to comply with the user’s specific multi-factor authentication (MFA) requirements.
Understanding the Attack Mechanism
To combat these threats, IT administrators, security operations center (SOC) teams, and organizational staff must develop a thorough understanding of the tactics employed by the Pink group. During an active attack in July 2026, it was reported that the phishing kit displayed a highly convincing Microsoft-branded recovery page. This recovery page featured a list of BIP-39 seed phrases—12 to 24 random words used for securing cryptocurrency wallets—with instructions prompting users to note them down for “identity backup.”
This presents a clear indicator of compromise since BIP-39 seed phrases hold no integration within Microsoft Entra ID. Such a crypto-style recovery prompt should immediately raise alarm bells regarding the legitimacy of a corporate login. The threat actors utilize this fabricated hurdle as a diversion, allowing them to register a permanent, phishing-resistant passkey to the real user’s profile. Once this covert access is secured, hackers can extract vast amounts of sensitive data from applications such as SharePoint and OneDrive.
Recommended Defense Strategies
Organizations can fortify their defenses against such sophisticated phishing attacks through several best practices. First and foremost, implementing strict conditional access policies that limit passkey registration to known corporate IP ranges can offer significant protection. Another crucial step involves monitoring logs for new passkeys that are assigned benign names, helping identify unusual activity that may indicate an ongoing breach. Additionally, establishing out-of-band verification protocols can ensure that users immediately terminate unsolicited IT compliance calls, further minimizing the risk of succumbing to a phishing attempt.
Concluding Thoughts
As the cyber threat landscape continues to evolve, the tactics utilized by groups like Pink underscore the necessity for organizations to remain vigilant. Understanding the mechanics behind these types of vishing attacks can empower employees at all levels to recognize potential threats and respond appropriately. With increasingly sophisticated methods in play, corporations must adapt and adopt proactive security measures, ensuring the protection of sensitive information and the integrity of their technological infrastructures.
About the Author
Carmen Estela, a Cybersecurity Research Analyst at Cyber Defense Magazine, emphasizes the critical importance of emerging cyber trends through her insightful analysis and research. Carmen, a candidate for the Women in Cybersecurity Award, recently completed her Master’s degree from the University of Central Florida and holds a Bachelor’s in Criminology from the University of Florida, along with certifications in Data Analytics and AI Fundamentals. Her commitment to advancing standards in governance, risk, and compliance within cybersecurity is exemplified by her participation in various industry events, such as BSides Orlando and BSides Jax. Moreover, Estela’s diverse background—as an adult protective investigator, police dispatcher, and legal intern—equips her with unique investigative skills that she applies across multiple sectors.
For inquiries or further engagements, Carmen Estela can be reached via her professional contact, which is available on Cyber Defense Magazine’s platform.

