Entra Passkey Enrollment Vishing Campaign Targets Microsoft 365 Users Across Multiple Sectors
What Happened – Threat actors are using voice‑based social engineering (“vishing”) to convince Microsoft 365 users to enroll a malicious Entra passkey. The attackers run a real‑time PHP phishing kit that mimics Microsoft’s enrollment flow, harvest MFA responses, and register a passkey under the attacker’s control.
Why It Matters for Compliance & Audit Readiness
- The scenario directly tests the effectiveness of SOC 2 CC6.1 – Logical Access Controls and CC6.2 – Authentication requirements; a successful vishing attack demonstrates a gap in user awareness and credential handling.
- Continuous evidence of access‑control testing, security‑awareness training completion, and incident‑response documentation is essential to prove that the organization mitigates social‑engineering risk.
- Verisq’s SOC 2 Access Controls capability provides automated collection of training logs, MFA policy enforcement evidence, and real‑time alerts that can be used as audit‑ready proof.
Who Is Affected – Organizations in food & beverage, technology, healthcare, automotive, construction, aviation, and any enterprise that has enabled Microsoft Entra passkey enrollment.
Recommended Actions
- Review and tighten MFA enrollment policies; require secondary verification for any passkey registration request.
- Deploy mandatory security‑awareness modules that cover vishing and credential‑phishing scenarios.
- Capture and retain logs of passkey enrollment campaigns (who initiated, who enrolled) as part of continuous control monitoring.
Source: BleepingComputer
Technical Notes – Attack vector: voice‑based phishing (vishing) → phishing kit (PHP) → credential & MFA capture → attacker‑controlled passkey registration. No CVE is involved; the abuse leverages a legitimate Microsoft admin feature introduced in May 2026. Source: same as above