HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Entra Passkey Enrollment Vishing Campaign Harvests MFA Credentials from Microsoft 365 Users

Threat actors are using voice‑based social engineering to trick Microsoft 365 users into enrolling attacker‑controlled passkeys, harvesting MFA responses in real time. The incident highlights gaps in SOC 2 access‑control and security‑awareness programs that must be documented for audit readiness.

LiveThreat™ Intelligence · 📅 July 08, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
6 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Entra Passkey Enrollment Vishing Campaign Targets Microsoft 365 Users Across Multiple Sectors

What Happened – Threat actors are using voice‑based social engineering (“vishing”) to convince Microsoft 365 users to enroll a malicious Entra passkey. The attackers run a real‑time PHP phishing kit that mimics Microsoft’s enrollment flow, harvest MFA responses, and register a passkey under the attacker’s control.

Why It Matters for Compliance & Audit Readiness

  • The scenario directly tests the effectiveness of SOC 2 CC6.1 – Logical Access Controls and CC6.2 – Authentication requirements; a successful vishing attack demonstrates a gap in user awareness and credential handling.
  • Continuous evidence of access‑control testing, security‑awareness training completion, and incident‑response documentation is essential to prove that the organization mitigates social‑engineering risk.
  • Verisq’s SOC 2 Access Controls capability provides automated collection of training logs, MFA policy enforcement evidence, and real‑time alerts that can be used as audit‑ready proof.

Who Is Affected – Organizations in food & beverage, technology, healthcare, automotive, construction, aviation, and any enterprise that has enabled Microsoft Entra passkey enrollment.

Recommended Actions

  • Review and tighten MFA enrollment policies; require secondary verification for any passkey registration request.
  • Deploy mandatory security‑awareness modules that cover vishing and credential‑phishing scenarios.
  • Capture and retain logs of passkey enrollment campaigns (who initiated, who enrolled) as part of continuous control monitoring.

Source: BleepingComputer

Technical Notes – Attack vector: voice‑based phishing (vishing) → phishing kit (PHP) → credential & MFA capture → attacker‑controlled passkey registration. No CVE is involved; the abuse leverages a legitimate Microsoft admin feature introduced in May 2026. Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →