An employee picks up the phone. The caller says they’re from IT, and it’s time to set up a passkey, the new login method that’s supposed to make phishing obsolete. Ten minutes later, the attacker owns the Microsoft 365 account, and the employee never typed a stolen password or clicked a shady link. That’s the whole point of the scam, and it’s why the cybersecurity industry needs to stop treating passkeys as a finish line.
The crew behind this, tracked as Pink, has been running the play against Entra ID tenants: vishing calls that impersonate internal IT, followed by a fake passkey enrollment page hosted on a lookalike subdomain. Everything after the call is theater, built to keep the target occupied while the attacker finalizes access in the background. No malware. No credential dump. Just a calm voice and a convincing web page.
Cybersecurity Built A Better Lock. Attackers Picked The Doorbell.
Passkeys exist because passwords are a disaster. They can’t be phished the way a password can, because there’s no secret to type into a fake login page. Security teams have spent the last two years pushing passwordless authentication as the fix for credential theft, and for the technology itself, that pitch holds up.
The problem is enrollment. Setting up a passkey is a process, not a moment, and processes have steps that a patient attacker can hijack. Pink doesn’t need to break the cryptography behind Entra passkeys. It only needs an employee who believes the person on the phone actually works in IT.
The caller poses as IT and says it’s time to set up a passkey. Everything after that is theater, built to keep the victim occupied while the attacker finalizes everything.
That’s the uncomfortable part. Every rollout of strong authentication creates a window where employees are told to expect exactly this kind of unfamiliar prompt. Attackers read the same rollout announcements your IT team sends, and they time their calls accordingly.
One Convincing Call Turns Into A Fully Owned Tenant
Once the target is on a subdomain designed to mimic the real enrollment flow, the attacker walks them through steps that look identical to the legitimate process. The victim thinks they’re confirming a new security feature. In reality, they’re handing over session control, and in some cases confirming a device the attacker registered to the account.
From there, this stops being a single-account problem. A hijacked Microsoft 365 account in an extortion campaign usually means access to email, SharePoint, Teams conversations, and whatever cloud storage the account touches. Extortion crews don’t need to encrypt anything to make money anymore. They just need to read your files and threaten to publish them.
This is also a threat detection blind spot by design. A real user logged into a real tenant, completing what looks like a routine security enrollment, doesn’t trip the alerts built for brute-force login attempts or impossible-travel logins. The attacker isn’t smashing through your firewall. They’re walking through the front door your own security policy told employees to open.
Harden The Enrollment Step Or The Passkey Rollout Backfires
None of this means passkeys are a bad idea. It means the enrollment process needs the same security hardening as any other privileged action, because right now it’s often treated as a one-time IT chore instead of an ongoing attack surface.
- Verify identity before any authentication method change, using a callback to a known number or an in-person check, never a number the caller provides.
- Restrict who can request passkey or MFA method changes, and require step-up verification for the request itself, not just the phone call.
- Alert on new authentication method registrations in real time, and route them into the same incident response queue as suspicious sign-ins.
- Train helpdesk and general staff specifically on vishing scripts, since generic phishing training rarely covers a live phone call impersonating internal IT.
- Audit conditional access policies so a newly enrolled device or method can’t immediately unlock high-value resources without additional scrutiny.
- Lock down self-service enrollment domains, and make sure employees know what your real enrollment URL looks like before you roll anything out.
Ongoing defense matters as much as the initial fix. Review authentication method change logs weekly, not just during incident response. Build a defense in depth approach where a compromised enrollment step doesn’t automatically translate into full tenant access; segment privileged roles so a single hijacked account can’t reach everything at once. Threat protection tooling that watches for anomalous authentication method registrations should sit alongside whatever you already run for endpoint and network monitoring, because this attack never touches the endpoint or the network perimeter at all.

The broader lesson applies well past this one campaign. Every security control you roll out creates a new set of steps employees haven’t seen before, and unfamiliarity is exactly what social engineers exploit. Cyber security teams love shipping the new control. They spend far less time hardening the rollout process itself, and that gap is where crews like Pink live.
Passkeys still beat passwords. But a security upgrade that gets social-engineered at the enrollment step isn’t a finished project, it’s a new attack surface with a better reputation.
Sources
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
