Voice‑Based Phishing Targets Microsoft 365 Passkey Enrollment
Disable automatic passkey enrollment prompts and enforce MFA for Microsoft 365 accounts.
Configure Microsoft 365 to require explicit user approval for passkey enrollment, audit user activity logs, and train staff on voice phishing tactics.
Summary
A threat actor has been targeting organizations across multiple sectors with voice‑based fake security requests that prompt Microsoft 365 users to enroll a new Entra passkey, aiming to carry out data extortion attacks. The actor, tracked by Okta under the moniker O‑UNC‑066, has deployed a panel‑controlled phishing kit that can target the passkey enrollment process. The kit generates realistic voice prompts that convince users to provide passkey credentials, which the attacker then uses to gain unauthorized access to corporate data. The attacks exploit the Entra passkey enrollment flow without exploiting any platform flaw, relying instead on social engineering and voice synthesis. The threat actor has been active for several months and has impacted organizations in finance, healthcare, and manufacturing. Microsoft has advised users to verify the authenticity of passkey prompts and to use multi‑factor authentication. Security teams should audit passkey enrollment settings and educate users about voice‑based phishing. The incident underscores the growing sophistication of social‑engineering attacks that leverage emerging voice‑AI technologies.
Key changes
- Voice‑based phishing targeting Microsoft 365 passkey enrollment
- Threat actor O‑UNC‑066 uses panel‑controlled kit
- Generates realistic voice prompts to trick users
- Exploits Entra passkey flow without platform flaw
- Active across finance, healthcare, manufacturing
- Microsoft advises verification of passkey prompts
- Security teams should audit passkey settings
- Highlights rise of voice‑AI social engineering