Since April 2026, the hacker group O-UNC-066 has been abusing the Passkey registration process for Microsoft 365 to gain access to corporate data via voice-phishing. The attacks target large companies across multiple industries and demonstrate how cybercriminals exploit legitimate security initiatives.
In an expert statement, Arkadiusz Krowczynski, Principal Product Acceleration Specialist at Okta, discusses a wave of attacks affecting multiple industries:
The introduction of Passkeys as a passwordless authentication method is intended to increase the security of corporate accounts. Current attack patterns, however, show that cybercriminals can exploit this technology as an entry point.
Since April 2026, the group known as O-UNC-066 has been conducting targeted attacks against Microsoft 365 customers. The targets are large companies in the food, technology, healthcare, automotive, construction, and aviation sectors. The primary goal of these campaigns is data theft and subsequent extortion of the affected organizations.
The attack vector is based on exploiting legitimate security initiatives. Since May 2026, administrators in corresponding IT environments have been able to activate so-called nudge campaigns that prompt users to set up a Passkey during regular login. The attackers register malicious domains containing the word “Passkey” and call target individuals directly. Over the phone, they pose as internal IT support and convince victims that urgent Passkey registration is required.
When users are directed to the prepared links, they land on target-group-specific subdomains that convincingly replicate familiar login pages—including correct company logos and background images. The phishing kit used is based on a manually controlled PHP panel. Through a heartbeat polling mechanism, the attacker guides the victim almost in real time through the various authentication phases.
This infrastructure enables dynamic adaptation of the fake website to the victim’s individual multi-factor authentication requirements. Whether time-based one-time passwords, SMS codes, or push notifications with number matching—the system presents exactly the input mask that the attacker needs in the background for the real login attempt. While the caller instructs the victim, the entered data becomes visible in the attacker’s panel and is simultaneously entered into the real corporate portal.
The most critical part of the attack is the registration. The phishing kit exploits end users’ lack of familiarity with the system-level Passkey enrollment process. Instead of calling up a genuine system dialog, the kit presents a fake page that prompts the user to save a “recovery key.” It generates a list of BIP-39 words and has the victim write them down. For confirmation, the last word must be entered manually. These phrases have no relevance to the regular registration process; they serve exclusively as a distraction. While the victim is occupied, the attacker unnoticed registers his own controlled Passkey in the victim’s real account. The victim believes they have set up a secure Passkey, while the attacker has built a persistent backdoor into the corporate network that requires neither the original password nor the user’s MFA device.
Security experts recommend that companies establish restrictive enrollment processes. The registration of new Passkeys or MFA methods should never be possible without additional verification and from unknown networks. Setup must be restricted to trusted environments or verified, managed endpoints. Alternatively, a temporary access code issued by support for adding new factors is necessary.
In addition, close monitoring is essential that triggers alerts for login registrations under unusual conditions. Equally critical is staff awareness of vishing tactics: employees must know what genuine system dialogs look like and that IT support never calls unsolicited to assist with login processes. Strict helpdesk guidelines are also required, where support requests are handled exclusively through defined ticket systems and user identities are always verified over the phone through secure callback routines.
The O-UNC-066 attack wave underscores that the introduction of modern authentication methods alone is insufficient. Companies must additionally secure the registration process and specifically sensitize their employees to voice-phishing.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de
