Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Hackers Deploy Fake Microsoft Entra Passkey Enrollment to Hijack Microsoft 365 Accounts

A threat actor is using a voice‑based phishing kit that mimics Microsoft Entra passkey enrollment, tricking users into granting attackers Microsoft 365 access. The scenario highlights gaps in access‑control policies that SOC 2 audits require organizations to remediate and evidence.

LiveThreat™ Intelligence · 📅 July 10, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

Hackers Deploy Fake Microsoft Entra Passkey Enrollment to Hijack Microsoft 365 Accounts

What Happened — A threat group (tracked by Okta as O‑UNC‑066) is running a panel‑controlled phishing kit that mimics Microsoft Entra passkey enrollment prompts. Victims receive a voice‑based “security request” that tricks them into registering a malicious passkey, granting the attackers persistent access to the victim’s Microsoft 365 tenant and enabling data‑extortion attempts.

Why It Matters for Compliance & Audit Readiness

  • The attack exploits weak access‑control policies and the lack of verification around new credential enrollment – a classic SOC 2 CC6.1/CC6.2 failure.
  • Continuous evidence of enrollment‑process monitoring and MFA enforcement is essential to demonstrate due diligence during a SOC 2 audit.
  • Security‑awareness training that covers emerging credential‑phishing vectors helps satisfy the “Security Awareness” control (CC7.1) and reduces the likelihood of successful social‑engineering.

Who Is Affected — Organizations across technology, finance, healthcare, and other sectors that use Microsoft Entra for identity management and Microsoft 365 for collaboration.

Recommended Actions

  • Enforce MFA and conditional‑access policies for any new passkey enrollment.
  • Audit Entra enrollment logs daily and set up alerts for anomalous registrations.
  • Run targeted phishing simulations that include passkey‑enrollment scenarios and refresh security‑awareness training.
  • Document the policy changes and monitoring evidence in your SOC 2 control repository.

Source: The Hacker News – Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

Technical Notes

  • Attack vector: Phishing (voice‑based social engineering) that hijacks the passkey enrollment flow.
  • No public CVE; the vulnerability is procedural – lack of enrollment verification.
  • Compromised data: Potential access to emails, files, and other Microsoft 365 assets, often leveraged for extortion.
📰 Original Source
https://thehackernews.com/2026/07/hackers-use-fake-microsoft-entra.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →