Hackers Deploy Fake Microsoft Entra Passkey Enrollment to Hijack Microsoft 365 Accounts
What Happened — A threat group (tracked by Okta as O‑UNC‑066) is running a panel‑controlled phishing kit that mimics Microsoft Entra passkey enrollment prompts. Victims receive a voice‑based “security request” that tricks them into registering a malicious passkey, granting the attackers persistent access to the victim’s Microsoft 365 tenant and enabling data‑extortion attempts.
Why It Matters for Compliance & Audit Readiness
- The attack exploits weak access‑control policies and the lack of verification around new credential enrollment – a classic SOC 2 CC6.1/CC6.2 failure.
- Continuous evidence of enrollment‑process monitoring and MFA enforcement is essential to demonstrate due diligence during a SOC 2 audit.
- Security‑awareness training that covers emerging credential‑phishing vectors helps satisfy the “Security Awareness” control (CC7.1) and reduces the likelihood of successful social‑engineering.
Who Is Affected — Organizations across technology, finance, healthcare, and other sectors that use Microsoft Entra for identity management and Microsoft 365 for collaboration.
Recommended Actions
- Enforce MFA and conditional‑access policies for any new passkey enrollment.
- Audit Entra enrollment logs daily and set up alerts for anomalous registrations.
- Run targeted phishing simulations that include passkey‑enrollment scenarios and refresh security‑awareness training.
- Document the policy changes and monitoring evidence in your SOC 2 control repository.
Source: The Hacker News – Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
Technical Notes
- Attack vector: Phishing (voice‑based social engineering) that hijacks the passkey enrollment flow.
- No public CVE; the vulnerability is procedural – lack of enrollment verification.
- Compromised data: Potential access to emails, files, and other Microsoft 365 assets, often leveraged for extortion.