HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Extortion Crew Hijacks Microsoft 365 Accounts via Fake Passkey Enrollment

A Pink extortion group leveraged vishing calls and a counterfeit Microsoft Entra passkey enrollment flow to capture credentials and MFA tokens, gaining persistent access to Microsoft 365 accounts. The incident underscores gaps in access‑control policies and security‑awareness training that SOC 2 audit programs must address.

LiveThreat™ Intelligence · 📅 July 09, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

Extortion Crew Hijacks Microsoft 365 Accounts via Fake Passkey Enrollment

What Happened — The Pink extortion group conducts vishing calls, posing as IT staff, and directs victims to a spoofed Microsoft Entra ID login page. After capturing the user’s credentials and MFA token, the attackers enroll a malicious “passkey” that lets them retain persistent access to the compromised Microsoft 365 account.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates a failure in access‑control policies and MFA enforcement that SOC 2 CC6 (Logical Access Security) is designed to mitigate and evidence.
  • Highlights the need for continuous monitoring of privileged‑account activity and proof of user‑training effectiveness—key audit artifacts for a defensible SOC 2 report.
  • Aligns directly with Verisq’s SOC 2 Access Controls capability, which helps organizations map, monitor, and document access‑control implementations and security‑awareness programs.

Who Is Affected – Enterprises of all sizes that use Microsoft 365 / Entra ID for identity management, spanning technology, finance, healthcare, and professional services.

Recommended Actions

  • Review and tighten MFA enrollment workflows; enforce conditional access that blocks passkey enrollment from unmanaged devices.
  • Deploy security‑awareness training that includes vishing and passkey‑lure simulations; track completion as audit evidence.
  • Enable continuous log‑monitoring for anomalous passkey registration events and generate alerts for privileged‑account changes.

Source: Help Net Security

Technical Notes – Attack vector: vishing → phishing kit → credential & MFA capture → malicious passkey enrollment. No CVE involved; the exploit leverages legitimate Microsoft Entra passkey‑registration features. Data exposed may include email, files, and internal communications. Source: same as above

📰 Original Source
https://www.helpnetsecurity.com/2026/07/09/microsoft-365-fake-passkey-setup-enrollment/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →