Extortion Crew Hijacks Microsoft 365 Accounts via Fake Passkey Enrollment
What Happened — The Pink extortion group conducts vishing calls, posing as IT staff, and directs victims to a spoofed Microsoft Entra ID login page. After capturing the user’s credentials and MFA token, the attackers enroll a malicious “passkey” that lets them retain persistent access to the compromised Microsoft 365 account.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a failure in access‑control policies and MFA enforcement that SOC 2 CC6 (Logical Access Security) is designed to mitigate and evidence.
- Highlights the need for continuous monitoring of privileged‑account activity and proof of user‑training effectiveness—key audit artifacts for a defensible SOC 2 report.
- Aligns directly with Verisq’s SOC 2 Access Controls capability, which helps organizations map, monitor, and document access‑control implementations and security‑awareness programs.
Who Is Affected – Enterprises of all sizes that use Microsoft 365 / Entra ID for identity management, spanning technology, finance, healthcare, and professional services.
Recommended Actions –
- Review and tighten MFA enrollment workflows; enforce conditional access that blocks passkey enrollment from unmanaged devices.
- Deploy security‑awareness training that includes vishing and passkey‑lure simulations; track completion as audit evidence.
- Enable continuous log‑monitoring for anomalous passkey registration events and generate alerts for privileged‑account changes.
Source: Help Net Security
Technical Notes – Attack vector: vishing → phishing kit → credential & MFA capture → malicious passkey enrollment. No CVE involved; the exploit leverages legitimate Microsoft Entra passkey‑registration features. Data exposed may include email, files, and internal communications. Source: same as above