Microsoft 365 Under Attack: Uncovering the Pink Hackers' Vishing Campaign (2026)

The world of cybersecurity is a complex and ever-evolving landscape, and the latest threat to emerge is a sophisticated vishing campaign targeting Microsoft 365's passkey enrollment process. This attack, orchestrated by the cyber extortion group Pink, highlights the evolving tactics of hackers and the need for organizations to stay vigilant.

What makes this campaign particularly insidious is the level of sophistication and mimicry. The hackers have crafted a phishing kit that closely resembles the legitimate Microsoft passkey enrollment process, complete with Microsoft branding and the targeted organization's branding. This level of realism makes it all the more challenging for users to discern the malicious intent.

The attack process begins with the threat actors registering domains that incorporate the word 'passkey' as part of a voice-enabled phishing scheme. They then call targeted users, pretending to be Microsoft, and persuade them to register a new passkey. Unsuspecting users are directed to a phishing kit that mimics the Microsoft passkey enrollment process, while the threat actors simultaneously register their own passkey in the targeted user's Microsoft account.

What makes this attack even more concerning is the hackers' financial motives. The group Pink, as they call themselves, is a financially motivated group, and their statement on their darknet leak site reveals their intent: 'Security, as you are undoubtedly aware, is an expensive undertaking, particularly when it has been neglected for some time. Our only goal is profit, and that is our only motivation. We know what your data is worth, and we expect to get our value out of it.'

The sectors being targeted by this campaign are diverse, including food and beverage, technology, healthcare, automotive, construction, and aviation. This broad reach underscores the potential impact of such attacks on various industries.

The domains used by the hackers to create their targeted subdomains include assignpasskey[.]com, deploypasskey[.]com, passkeydeploy[.]com, passkeyadd[.]com, and setpasskey[.]com. These subdomains are designed to mimic the targeted organization's domain, further increasing the likelihood of successful phishing attempts.

This vishing campaign serves as a stark reminder of the evolving nature of cyber threats and the need for organizations to adopt robust security measures. As hackers become more sophisticated, it is crucial to stay informed, educate users, and implement multi-factor authentication and other security protocols to mitigate the risk of falling victim to such attacks.

Microsoft 365 Under Attack: Uncovering the Pink Hackers' Vishing Campaign (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Rev. Leonie Wyman

Last Updated:

Views: 6485

Rating: 4.9 / 5 (79 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Rev. Leonie Wyman

Birthday: 1993-07-01

Address: Suite 763 6272 Lang Bypass, New Xochitlport, VT 72704-3308

Phone: +22014484519944

Job: Banking Officer

Hobby: Sailing, Gaming, Basketball, Calligraphy, Mycology, Astronomy, Juggling

Introduction: My name is Rev. Leonie Wyman, I am a colorful, tasty, splendid, fair, witty, gorgeous, splendid person who loves writing and wants to share my knowledge and understanding with you.