Filed under: Cybersecurity • Phishing • July 2026
What happened
Since April 2026, a criminal crew that researchers track as “Pink” has been calling employees at small and mid-sized companies, posing as Microsoft or internal IT and claiming a “security upgrade” is required. On the phone, they walk the victim through a fake Microsoft 365 login and passkey-enrollment page in real time, capture the password and the MFA approval, sign in to the real account, then quietly register their own passkey so they keep access even after the victim changes their password. There is no software bug here — the attackers simply abuse the legitimate passkey feature Microsoft turned on in May. Security firm Okta detailed the campaign on July 8, 2026.
Why it matters to your business
Passkeys and multi-factor authentication are exactly what we tell every client to turn on — and this attack is built to defeat both by fooling a person on the phone instead of breaking any software. Once the crooks plant their own passkey, they own that mailbox and can silently read and download everything in SharePoint and OneDrive: your invoices, client records, tax documents, and banking details. For a Phoenix small business, one convincing call to a receptionist or bookkeeper can turn into wire fraud or a reportable data breach.
What to do this week
Tell every employee plainly: MicroOne (or your IT provider) will never phone you and walk you through adding a passkey or approving an MFA prompt — if you get that call, hang up and call us back on a number you already have. In the Entra admin center, review each user’s registered sign-in methods (Users > select the user > Authentication methods) and remove any passkey or authenticator you don’t recognize. Then tighten who can enroll: Entra ID > Security > Authentication methods > Passkey (FIDO2), and restrict registration to trusted devices. Finally, turn on a Conditional Access rule that blocks sign-ins from countries you don’t do business in.
The bigger picture
The lock on your accounts is only as strong as the person who can be talked into opening it, and attackers have simply moved from email to the phone. Coaching your team to recognize the pitch is now as important as any software setting. → Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back
Not sure who could add a passkey to your Microsoft 365 accounts right now? Book a free consult → https://micro1tech.com/contact/