Microsoft 365 users are under threat from a sophisticated vishing campaign targeting their passkey enrollment process. The cyber extortion group, Pink, is exploiting Microsoft's own security measures to gain access to victim networks. By impersonating Microsoft's login pages and using well-crafted phishing kits, Pink is able to deceive users into registering new passkeys, while simultaneously registering their own passkey in the victim's account. This campaign is particularly insidious because it leverages Microsoft's recent security upgrade reminders, making it seem more legitimate and increasing the chances of success. The hackers' motives are clear: financial gain. They state their goal is profit, and they are aware of the value of the data they steal. The targeted sectors include food and beverage, technology, healthcare, automotive, construction, and aviation, indicating a wide range of potential victims. This widespread attack highlights the importance of user vigilance and robust security measures to protect against such threats. As Pink's activities demonstrate, even well-intentioned security upgrades can be exploited, emphasizing the need for constant vigilance and education in cybersecurity.