July 12, 2026 - 8 min read

By PhishClean Research Team

Attackers Are Now Phishing Your Passkey Enrollment, Not Just Your Password

Passkeys are supposed to be phishing-resistant - and they are. So attackers changed the target. A campaign Okta is tracking calls employees, talks them through a fake passkey setup page, and quietly registers the attacker's own passkey on the real account.

Okta's threat intelligence team reported in July 2026 that a threat actor it tracks as O-UNC-066 has been running a voice-phishing ("vishing") campaign aimed at Microsoft 365 customers since around April 2026. Instead of trying to steal a password over a fake page and hoping there is no second factor, this campaign goes after the moment you set up a passkey. Reporting from BleepingComputer, SecurityWeek, and others describes targeting across food and beverage, technology, healthcare, automotive, construction, and aviation - with data extortion as the goal.

Why go after passkey enrollment?

A passkey is bound to a real domain, so a fake look-alike login page cannot capture and replay it - that is the whole point of passkeys. But enrollment is a human moment. If an attacker can convince you that you "need to register a new passkey," they do not have to beat the cryptography. They just have to be standing next to you, virtually, while you do it - and slip their own key in instead.

How the attack reportedly plays out

A real, unsolicited phone call is doing the persuading here. The page only has to look convincing for a minute while someone talks you through it. Slow down: nobody legitimate needs to call you and watch you set up a passkey.

The dangerous part: it survives a password reset

Because the attacker registers their own passkey on your real account, resetting your password does not necessarily lock them out. That is what makes this worth the effort for the attackers, who reportedly run a data-leak site and give victims short payment deadlines using the very accounts they compromised.

What to check before you enroll anything

If you think you were caught

Review the passkeys and security methods registered on your account and remove any you do not recognize. Reset your password, sign out all sessions, and check recent sign-ins and app grants. Then report it - because the attacker's registered passkey needs to be removed by someone who knows to look for it, a routine reset can leave the door open.

Why a registered credential beats a stolen password

A stolen password is perishable. It stops working the moment it is reset, and a decent conditional-access policy can strangle it before then. A credential the attacker registers on the real account is different: it is the provider's own strong authentication working exactly as designed, just for the wrong person. It survives password resets, does not trip the heuristics that a raw password replay can, and from the outside looks like the account owner using modern security. The same durability logic applies to stolen session tokens, which is why post-incident cleanup has to cover active sessions and registered methods, not just the password - see our breakdown of session hijacking attacks for that half of the problem.

Questions to ask before approving any enrollment prompt

Passkeys, authenticator apps, and security keys all share one safe rule: enrollment should only ever happen on your terms. Before approving anything, ask:

What IT teams can do to blunt enrollment phishing

The most valuable control is a promise, stated plainly and repeated: we will never call you and ask you to enroll a security method. Once that rule exists, every such call is self-evidently an attack, and employees no longer have to judge how convincing the caller sounds. Beyond that, alert on new authentication-method registrations - especially a new passkey appearing shortly after an unusual sign-in - review registered methods as a standard part of any account investigation, and give staff a fast, blame-free way to report a call they cut short. The attacker's model depends on the enrollment moment being unremarkable; instrumenting that moment takes the quiet part away.

Where the browser fits in

The call is out of the browser's reach, but the fake enrollment page is not. PhishClean analyzes the page you actually land on - flagging lookalike and brand-embedding domains (including hostnames that pad a real brand with words like "passkey"), suspicious login forms, and short-lived hosts - at the moment you are being rushed to trust it.

Don't let a convincing call rush you onto a fake page

PhishClean flags lookalike domains and fake login flows in the browser, so a page handed to you mid-call gets a second opinion.

Install PhishClean Free

Last updated:

Share This Guide

If this helped, share it with someone who would benefit from it, or subscribe for new browser-security guides from PhishClean.