HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Hackers Deploy Fake Microsoft Entra Passkey Enrollment to Hijack Microsoft 365 Accounts

A threat actor is using a voice‑based phishing kit that mimics Microsoft Entra passkey enrollment, tricking users into granting attackers Microsoft 365 access. The scenario highlights gaps in access‑control policies that SOC 2 audits require organizations to remediate and evidence.

LiveThreat™ Intelligence · 📅 July 10, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

Hackers Deploy Fake Microsoft Entra Passkey Enrollment to Hijack Microsoft 365 Accounts

What Happened — A threat group (tracked by Okta as O‑UNC‑066) is running a panel‑controlled phishing kit that mimics Microsoft Entra passkey enrollment prompts. Victims receive a voice‑based “security request” that tricks them into registering a malicious passkey, granting the attackers persistent access to the victim’s Microsoft 365 tenant and enabling data‑extortion attempts.

Why It Matters for Compliance & Audit Readiness

  • The attack exploits weak access‑control policies and the lack of verification around new credential enrollment – a classic SOC 2 CC6.1/CC6.2 failure.
  • Continuous evidence of enrollment‑process monitoring and MFA enforcement is essential to demonstrate due diligence during a SOC 2 audit.
  • Security‑awareness training that covers emerging credential‑phishing vectors helps satisfy the “Security Awareness” control (CC7.1) and reduces the likelihood of successful social‑engineering.

Who Is Affected — Organizations across technology, finance, healthcare, and other sectors that use Microsoft Entra for identity management and Microsoft 365 for collaboration.

Recommended Actions

  • Enforce MFA and conditional‑access policies for any new passkey enrollment.
  • Audit Entra enrollment logs daily and set up alerts for anomalous registrations.
  • Run targeted phishing simulations that include passkey‑enrollment scenarios and refresh security‑awareness training.
  • Document the policy changes and monitoring evidence in your SOC 2 control repository.

Source: The Hacker News – Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

Technical Notes

  • Attack vector: Phishing (voice‑based social engineering) that hijacks the passkey enrollment flow.
  • No public CVE; the vulnerability is procedural – lack of enrollment verification.
  • Compromised data: Potential access to emails, files, and other Microsoft 365 assets, often leveraged for extortion.
📰 Original Source
https://thehackernews.com/2026/07/hackers-use-fake-microsoft-entra.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →