CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Entra passkey enrollment vishing targets Microsoft 365 users

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2185

As cited

Copy frozen at (site build).

threat intel

Entra passkey enrollment vishing targets Microsoft 365 users

A threat actor is targeting Microsoft 365 users with vishing (voice phishing) attacks that impersonate security personnel and request enrollment of a new Entra passkey. The campaign affects organizations across multiple sectors.

Why it matters: Microsoft 365 administrators and employees should be aware of this vishing technique targeting Entra ID, as successful passkey enrollment by attackers could enable unauthorized access to cloud infrastructure and business-critical data.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Entra passkey enrollment vishing targets Microsoft 365 users

A threat actor is targeting Microsoft 365 users with vishing (voice phishing) attacks that impersonate security personnel and request enrollment of a new Entra passkey. The campaign affects organizations across multiple sectors.

Why it matters: Microsoft 365 administrators and employees should be aware of this vishing technique targeting Entra ID, as successful passkey enrollment by attackers could enable unauthorized access to cloud infrastructure and business-critical data.

VendorsMicrosoftOkta
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary