Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
A sophisticated hacking group has been targeting various organizations with a cunning phishing scheme involving fake Microsoft Entra passkey enrollments. They're using voice-based scams to trick Microsoft 365 users into setting up these bogus passkeys, which ultimately lets them gain unauthorized access to sensitive data for potential extortion. This threat, identified by Okta as O-UNC-066, highlights a serious security gap in enterprise authentication processes, underscoring the need for improved vigilance and advanced security measures to protect against such advanced phishing attacks.
Original Source
Read the full article at Thehackernews →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.