Breaking News

Source

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra passkey with an aim to carry out data extortion attacks. 

The threat actor, tracked by Okta under the moniker O-UNC-066, has deployed a panel-controlled phishing kit that’s capable of targeting the passkey enrollment process. The activity has singled out food and beverage, technology, healthcare, automotive, construction, and aviation industries.

“The threat actor registers domains that incorporate the word passkey as part of a voice-enabled phishing (‘vishing’) scheme,” Okta researcher Houssem Eddine Bordjiba said. “The threat actor then calls targeted users on the phone in an attempt to persuade them that they need to register a new passkey.”

Users are then directed to a phishing kit that’s identical to the Microsoft passkey enrollment process, giving the impression that they are adding a passkey with Microsoft, when, in reality, the threat actor registers their own passkey against their Microsoft account, granting them unauthorized access.

Read the full article

Key Points that Matter

  1. Cyberattacks increasingly combine multiple attack channels. Threat actors are blending phishing, QR codes, and voice-based social engineering to steal credentials and gain initial access more effectively.
  2. Initial access brokers exploit human trust, not technical vulnerabilities. Once credentials are compromised, attackers often pivot to voice calls impersonating IT support or trusted personnel to escalate privileges and bypass security controls.
  3. Every communication channel must be treated as part of the attack surface. Email, collaboration platforms, QR codes, and voice work together in modern attack campaigns, making Voice Security an essential layer of a comprehensive cyber defense strategy.

You Can Stop Voice-Based Threats

The Voice Channel has become the most exploited pathway for threat actors. Voice Security is no longer a nice to have, but a critical mandate.

Mutare’s Voice Security Platform defends the voice channel as critical infrastructure. Operating as a technical control at the network edge, it stops vishing, social engineering, spoofed calls, spam storms, and GenAI-powered attacks.

We understand that every organization is at a different stage of its Voice Security journey.
Some are just beginning to understand the risks. Others are evaluating solutions or validating technologies. Take a moment to check out Test Drive to choose your path towards understanding the voice security landscape and learning about a comprehensive defense solution.

Learn More About Voice Security

We’ve curated the latest information and events about Voice Security:

Articles

Voice Security Has Reached a Tipping Point

The 2026 Voice Threat Survey reveals why voice can no longer be treated as an overlooked communications channel. It has become one of the fastest-growing cyber threat vectors in the enterprise.

Events

WEBINAR: AI-Ready Voice Security

What was once limited to nuisance robocalls has evolved into a continuous stream of unwanted voice traffic, now amplified by automation, spoofing, and AI-driven attack campaigns.

ViVE, Feb 2026, Los Angeles, CA

Please join us in Los Angeles February 22-25 and connect with a member of the Mutare Team to discuss patient experience, patient care, and risk management.

Case Studies