Executive Summary
In April 2026, a threat actor identified as O-UNC-066, operating under the extortion brand 'Pink,' initiated a vishing campaign targeting Microsoft 365 users across multiple sectors, including food and beverage, technology, healthcare, automotive, construction, and aviation. The attackers impersonated IT personnel, contacting employees by phone and instructing them to enroll a new Microsoft Entra passkey for security purposes. Victims were directed to phishing websites mimicking legitimate Microsoft enrollment portals, where attackers captured credentials and multi-factor authentication (MFA) responses. Subsequently, the attackers registered passkeys under their control, gaining unauthorized access to victims' Microsoft accounts and exfiltrating data from services like SharePoint and OneDrive. (bleepingcomputer.com)
This incident underscores a growing trend of sophisticated social engineering attacks exploiting emerging authentication technologies. The use of real-time phishing kits capable of adapting to various MFA methods highlights the evolving tactics of cybercriminals. Organizations must remain vigilant, as such attacks can lead to significant data breaches and financial extortion. (bleepingcomputer.com)
Why This Matters Now
The 'Pink' extortion group's campaign demonstrates the increasing sophistication of social engineering attacks targeting authentication processes. As organizations adopt new security measures like passkeys, attackers are quickly adapting their tactics to exploit these systems. Immediate attention is required to enhance user education, implement robust verification processes, and monitor for anomalous activities to prevent unauthorized access and data breaches. (bleepingcomputer.com)
Attack Path Analysis
The attacker initiated the attack by impersonating IT support personnel and contacting Microsoft 365 users via phone calls, instructing them to enroll a new Entra passkey. This social engineering tactic led victims to a phishing site mimicking the legitimate Microsoft passkey enrollment portal, where they unknowingly provided their credentials and multi-factor authentication (MFA) responses. With these credentials, the attacker gained unauthorized access to the victims' Microsoft 365 accounts. Subsequently, the attacker registered a passkey under their control, establishing persistent access. The attacker then exfiltrated data from SharePoint and OneDrive services. Finally, the attacker threatened to leak the stolen data unless a ransom was paid, aiming to extort the victims.
Kill Chain Progression
Initial Compromise
Description
The attacker impersonated IT support personnel and contacted Microsoft 365 users via phone calls, instructing them to enroll a new Entra passkey. Victims were directed to a phishing site mimicking the legitimate Microsoft passkey enrollment portal, where they unknowingly provided their credentials and multi-factor authentication (MFA) responses.
MITRE ATT&CK® Techniques
Phishing: Spearphishing Voice
Phishing for Information: Spearphishing Voice
Valid Accounts
Brute Force
Application Layer Protocol
Archive Collected Data
Automated Exfiltration
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that all system components are protected from known vulnerabilities by installing applicable security patches
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Microsoft 365 dependency and HIPAA compliance requirements create severe risk from passkey enrollment vishing targeting credential theft and data exfiltration.
Food/Beverages
Explicitly targeted by O-UNC-066 Pink extortion gang using vishing attacks to compromise Microsoft 365 accounts for SharePoint data theft.
Information Technology/IT
High Microsoft 365 adoption makes IT sector prime target for sophisticated passkey enrollment social engineering attacks bypassing traditional MFA protections.
Automotive
Specifically targeted industry facing credential theft attacks through fake security upgrade calls compromising Microsoft Entra identity and access management systems.
Sources
- Entra passkey enrollment vishing targets Microsoft 365 usershttps://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/Verified
- Register a Microsoft Entra passkey on Windows (preview)https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-register-entra-passkey-windowsVerified
- Passkeys aren’t the finish line: Eliminating fallbacks and fixing recoveryhttps://techcommunity.microsoft.com/blog/microsoft-entra-blog/passkeys-aren%E2%80%99t-the-finish-line-eliminating-fallbacks-and-fixing-recovery/3627345/replies/4517618Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent credential theft via social engineering, it could limit the attacker's subsequent access within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could limit the attacker's ability to escalate privileges by enforcing strict access controls and segmenting workloads.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could limit the attacker's ability to move laterally by enforcing strict segmentation and monitoring internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could limit the attacker's ability to maintain command and control by providing comprehensive monitoring and control over cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could limit the attacker's ability to exfiltrate data by controlling and monitoring outbound traffic.
With Aviatrix CNSF controls in place, the attacker's ability to exfiltrate data would likely be constrained, reducing the potential impact of data leakage and extortion.
Impact at a Glance
Affected Business Functions
- Email Communications
- Document Management
- Collaboration Platforms
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of sensitive corporate data stored in Microsoft 365, including emails, documents, and internal communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement robust user education programs to recognize and report vishing attempts.
- • Enforce strict identity verification processes for IT support interactions.
- • Utilize multi-factor authentication (MFA) methods that are resistant to social engineering attacks.
- • Monitor for anomalous access patterns and implement real-time alerting mechanisms.
- • Regularly review and update access controls to minimize the risk of unauthorized access.



