
A group of scammers has been running a sophisticated phone-based attack since April 2026, calling employees at companies and pretending to be from their IT security team. The callers convince workers that they need to register a new login key — called a “passkey” — to keep their Microsoft 365 account secure. But the link they send goes to a fake Microsoft sign-in page, and if the employee follows the steps, the attacker gains permanent access to the victim’s work email, files, and messages.
This attack was uncovered by security researchers at Okta and is tracked as threat actor O-UNC-066. Unlike typical phishing emails, this campaign uses a real human voice, making it far more convincing than a standard scam message. Organizations in food and beverage, technology, healthcare, automotive, construction, and aviation have all been targeted. The attackers’ goal is data extortion — they steal sensitive company files and threaten to publish them unless paid.
How to check if you’re affected
Affected products include Microsoft 365 accounts used at your workplace. If you received an unexpected phone call from someone claiming to be IT and asking you to click a link or scan a QR code to register a new login method, treat this as a serious red flag.
- Sign in to your Microsoft 365 account and review your registered security keys and passkeys under your security settings. Remove any entry you do not recognize.
- If you received such a call and followed the caller’s instructions, contact your IT team immediately and ask them to revoke your active sessions.
- Never register a new passkey, approve a sign-in prompt, or click a security link unless you personally initiated the action.
