// OktaMEDIUM
Okta has issued a security advisory warning organizations of an ongoing vishing campaign exploiting Microsoft 365 users. The threat actor, tracked as O-UNC-066 (also known as Pink/CL-CRI-1147), has been conducting voice-enabled attacks since April 2026 to harvest Microsoft Entra ID credentials. Attackers direct victims to fake passkey enrollment pages designed to mimic legitimate Microsoft interfaces. Multiple sectors including automotive, aviation, healthcare, and technology have been targeted, primarily for data extortion purposes.
// Get alerts for Okta