SHIELD: ACTIVE // NETWORK SECURE

Social Engineering: Pink Extortion Crew Hijacks Microsoft 365 Accounts via Fake Passkey Setup

Social Engineering: Pink Extortion Crew Hijacks Microsoft 365 Accounts via Fake Passkey Setup

Executive Summary

A highly sophisticated, active social engineering campaign has been uncovered targeting enterprise Microsoft 365 and Microsoft Entra ID environments. Detailed in a threat report on July 12, 2026, by Help Net Security, a cyber extortion group tracked as Pink is successfully bypassing traditional multi-factor authentication (MFA) controls by tricking employees into registering fake passkeys on their accounts. The attack utilizes a highly convincing "vishing" (voice phishing) phone call, where the attacker poses as a corporate IT support engineer assisting the employee with mandatory passkey enrollment. Through real-time manipulation, the victim is guided to scan an attacker-supplied QR code, which silently registers the attacker’s device as the primary, authorized passkey for the victim's Microsoft 365 account. This allows the Pink crew to establish persistent, passwordless access to corporate email tenants, enabling downstream business email compromise (BEC) and data-theft extortion campaigns.

Deep-Dive Technical Analysis

The transition to passwordless authentication (such as passkeys utilizing FIDO2 and WebAuthn standards) has been widely promoted as a robust defense against traditional credential-harvesting and phishing attacks. Because passkeys are cryptographically bound to a specific domain and require local device biometrics, they cannot be harvested via fake login portals. However, the Pink crew’s campaign demonstrates a critical, structural vulnerability: the passkey enrollment phase remains highly susceptible to social engineering.

A forensic reconstruction of the passkey hijacking campaign reveals a highly calculated, multi-step execution path:

1. The Vishing Call Entry Vector: Attackers initiate contact by placing a direct phone call to an employee. Utilizing spoofed corporate numbers and pre-harvested LinkedIn data, the caller establishes trust by posing as a representative from the company's internal IT helpdesk, claiming that the employee must immediately register a mandatory security passkey to comply with corporate security updates.

2. Initiating the Legitimate Entra ID Enrollment: While keeping the victim occupied on the phone, the attacker logs into Microsoft Entra ID using the employee's pre-harvested basic credentials (often obtained from dark web dumps or brute-forcing) and initiates a legitimate "Add a security key" or "Register passkey" request.

3. The Fake Registration Prompt: Under Microsoft's standard enrollment flow, a QR code or an authorization prompt is generated to pair the new passkey. The attacker transmits this QR code directly to the victim (via email, SMS, or shared screen), instructing them to scan it with their mobile device or follow the on-screen prompts to "complete the security synchronization."

4. Registering the Attacker's Passkey: In reality, scanning the QR code authorizes and registers the attacker’s physical security key or device as the primary passkey for the victim's account. Because Entra ID trusts the registration as a user-authorized event, the pairing succeeds.

5. Achieving Persistent, MFA-Bypassing Access: Armed with an authorized passkey registered to their own device, the Pink crew can log into the victim's Microsoft 365 account at will. This completely bypasses traditional MFA push notifications and password-reset alerts, granting the attackers unrestricted access to corporate mailboxes, SharePoint directories, and internal SaaS databases.

By exploiting the human element during the registration phase, the attackers turn the very tool meant to secure the account into a persistent, unmonitored backdoor.

Industry Impact and Recommendations

The Pink vishing campaign marks a dangerous advancement in social engineering tactics. When threat actors can manipulate employees into registering unauthorized hardware tokens, traditional detection systems are bypassed, as the subsequent malicious logins appear completely legitimate and cryptographically verified.

We recommend that all system administrators, CISOs, and enterprise identity security leads implement the following mitigations:

* Enforce Strict Out-of-Band Verification for IT Support: Implement rigid verification protocols for all internal IT support calls. Instruct employees to never register passkeys, scan QR codes, or authorize MFA prompts during unsolicited phone calls. Mandate that employees verify the identity of any IT caller via separate, out-of-band communication channels (such as Slack or corporate directory lookups).

* Restrict Self-Service Passkey Registration: Limit the ability of standard employees to register new security keys or passkeys without strict administrative approval. Standardize policies requiring that all new passkey enrollments are conducted in-person by verified IT staff, or verified through a secure, multi-stage administrative validation workflow.

* Monitor for Anomalous Passkey Registration Events: Configure Microsoft Entra ID logging to capture all raw passkey and security key registration events. Set up real-time SIEM alerts to flag any instance where a passkey is registered from an uncharacteristic IP address, an unmanaged device, or immediately following a failed login attempt.

* Conduct Regular, Realistic Vishing Simulation Training: Actively train your workforce. Execute periodic, realistic vishing simulations mimicking IT helpdesk passkey enrollment requests to help employees recognize and report active social-engineering campaigns before they can succeed.

References:

* Help Net Security — Week in review: Accenture data breach, great open-source...

* Check Point Research — 6th July Threat Intelligence Report

Reported by:

Person

Category: Cyber Security Intelligence