Pink extortion group uses fake help-desk calls and MFA phishing to steal Microsoft 365 and cloud data

A newly identified extortion group called Pink is calling employees while pretending to be IT support, then stealing account credentials and company data to demand payment. Palo Alto Networks Unit 42 says the group, tracked as CL-CRI-1147 and likely linked to the criminal network known as The Com, uses voice phishing and fake help-desk interactions to capture passwords and multifactor authentication (MFA) approvals, then raids services such as SharePoint, OneDrive, and Microsoft Teams. Unit 42 said Pink's leak site went live on May 31 and published domains and IP addresses tied to the campaign as indicators of compromise.
Why it matters: This matters to organizations that rely on cloud productivity tools because attackers do not need malware or software flaws if they can talk staff into handing over access. Companies should warn staff about unsolicited help-desk calls, tighten help-desk identity checks, review Microsoft 365 logs, and block or investigate the listed phishing infrastructure immediately.

Sources

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
Ionut Arghire 2026.07.10 95% relevant
This is a direct update on the same underlying campaign and actor, adding Okta’s details on Pink/O-UNC-066 using voice calls, fake Microsoft Entra passkey enrollment pages, real-time operator-driven phishing, and attacker passkey registration to take over Microsoft 365 accounts.
Entra passkey enrollment vishing targets Microsoft 365 users
Bill Toulas 2026.07.08 95% relevant
This article adds specific tradecraft for the same Pink extortion activity: vishing calls that abuse Microsoft Entra passkey registration campaigns, a phishing kit that imitates Entra enrollment in real time, and post-login passkey registration under attacker control to persist access and steal SharePoint and OneDrive data.
Pink is the latest goon squad to use fake helpdesk calls to steal creds
2026.06.04 100% relevant
The article establishes a distinct new threat story: a newly branded extortion cluster, Pink, with a named leak site, tradecraft, likely affiliation, and concrete indicators of compromise.
← Back to all stories