The Phishing-Resistant Paradox: How Attackers Weaponized Passkeys (And How to Stop Them)
Date: 2026-08-04
Author: Anders Adolfsson, Product Manager

The cybersecurity industry has spent the last few years championing passkeys as the ultimate, phishing-resistant silver bullet. Based on FIDO2 public key cryptography, passkeys are mathematically resistant to traditional credential harvesting.
But threat actors are nothing if not adaptable. In a reminder that a security chain is only as strong as its weakest link, a sophisticated threat group has turned the transition to passkeys into a weapon.
The Incident: O-UNC-066 and the Passkey Vishing Campaign
According to a recent report by Okta Threat Intelligence, a threat actor tracked as O-UNC-066 (also known as “Pink” or CL-CRI-1147) has been executing a highly coordinated voice phishing (“vishing”) campaign since April 2026. Their primary goal? Data extortion. They have successfully targeted enterprise organizations across multiple sectors, including healthcare, technology, aviation, and construction.
The attack exploits user unfamiliarity with passkeys and perfectly times its lures with Microsoft’s recent rollout of automated passkey registration “nudges.” The attackers impersonate internal IT helpdesk personnel over the phone and guide victims to realistic, employer-branded lookalike subdomains.
Using a custom, operator-controlled phishing kit, the attacker intercepts the victim’s credentials and standard multi-factor authentication (MFA) codes in real-time. Crucially, the attacker then uses those intercepted credentials to log into the victim’s actual Microsoft account and registers their own passkey.
To keep the victim distracted during this process, the phishing kit displays a fake recovery page presenting a list of BIP-39 seed phrases (typically used for cryptocurrency wallets), asking the user to verify words.
The result? The attacker gains persistent, highly privileged, and ironically “phishing-resistant” access to the victim’s environment.
The Bootstrapping Vulnerability
How does a technology designed to stop phishing get bypassed by a phishing call? The flaw isn’t in the passkey itself; it’s in the enrollment process.
This is known as the “bootstrapping” problem. Before a system can issue a highly secure passkey, it has to ask, “Are you really who you say you are?”
By default, native self-service enrollment workflows often fall back on older, weaker methods to initially prove a user’s identity. If an SMS code or a simple push notification is all it takes to authorize the creation of a new passkey, attackers will simply intercept the SMS code, hijack the session, and mint a key for themselves.
The Antidote: Breaking the Loop with a CMS
The most effective way to eliminate this bootstrapping vulnerability is to replace open self-service workflows with a Credential Management System (CMS).
A CMS shifts the security model away from trusting the user’s initial clicks and relies instead on tightly controlled, policy-driven administrative workflows. By managing the lifecycle of the credential outside of the standard user login flow, a CMS effectively breaks the real-time loop that attackers like O-UNC-066 rely on.
Additionally, there are steps in Entra ID you can take to strengthen your defenses:
- Disable self-service setup of passkeys.
- Disable weak authentication methods. This is done using Authentication Strengths, where you create a profile that only allows FIDO2 security keys for authentication.
- Finally, limit the devices in use. Limit to only the specific AAGUIDs of your devices with the feature “Restrict specific keys”.

The Takeaway
Passkeys are still the future of identity security, but we must be diligent in every step of the process, especially the bootstrapping phase, which is now actively under attack. Moving to a phishing-resistant authentication standard requires a phishing-resistant enrollment process.
If your organization is pushing passkey adoption without the centralized oversight and verification, strict lifecycle controls provided by a Credential Management System, you aren’t just leaving a door unlocked, you might be handing the attackers the keys.
About Author

Anders Adolfsson is Versasec’s Global Product Manager. He is an experienced solutions architect with extensive experience in bringing products and ideas to the market, mostly with new and emerging technologies for Fortune 500 enterprises. Anders has been with Versasec for nearly 10 years and brings to his position more than 30 years of experience in IT, sales, pre-sales, services, project management, and development. Before being Product Manager, Adolfsson worked as a Technical Consultant in the Nordics Region and as IT Director.
vSEC:CMS
Our product suite provides all the software tools to administrate and manage credentials in a secure and convenient way.
Schedule a Strategic Call
Versasec provides enterprise credential management to accelerate phishing-resistant MFA. Our solutions enable customers to securely authenticate, issue and manage user credentials more cost effectively. Schedule a 1:1 Strategic Call With Our Identity Experts.
Job Openings
We are always looking for new exceptional persons to join our team! Find out more about our job openings.
