A threat actor known as O‑UNC‑066 is impersonating Microsoft security staff through phone-based “vishing” calls to trick Microsoft 365 users into enrolling a fake Entra passkey, allowing attackers to take over accounts. The group uses a highly interactive phishing kit that mirrors Microsoft’s real passkey setup flow, guiding victims through MFA challenges in real time while secretly registering the attacker’s own passkey. Okta and Palo Alto Networks link the activity to a broader cybercrime collective involved in data extortion operations.