Your employees can spot a suspicious email. Fewer of them are prepared for the phone call that follows: someone claiming to be from IT, asking them to register a new passkey, and in minutes the attacker has their Microsoft 365 credentials. This is the active O-UNC-066 campaign, and it targets sectors that form the backbone of Canadian enterprise, including healthcare, technology, and food and beverage. Effective security awareness for Canadian organizations now means testing employee defences against voice-based social engineering, not just email lures.
The O-UNC-066 Campaign: A Phone Call as a Weapon
Since April 2026, the threat actor tracked by Okta as O-UNC-066, and operating the extortion brand Pink, has been calling employees at organisations across the food and beverage, technology, healthcare, automotive, construction, and aviation sectors. The pretext is simple: the caller poses as IT support and tells the target they must immediately enrol a new Microsoft Entra passkey. Targets are directed to a phishing URL that includes the word “passkey” in the domain name, designed to closely mimic Microsoft’s legitimate enrollment page.
The kit is not automated. A live attacker controls a PHP panel and guides the victim through each step in real time, adapting the page flow based on the target’s MFA configuration. Once inside, Pink moves quickly to exfiltrate data from SharePoint and OneDrive. A public data leak site launched May 31, 2026 adds pressure: Pink posts stolen data samples and enforces 72-hour payment deadlines. Palo Alto Networks’ Unit 42 attributes Pink to The Com, the same loose criminal network that produced Scattered Spider, ShinyHunters, and LAPSUS$.
Voice Phishing Is Now the Second-Biggest Threat Vector
This campaign is not an anomaly. Mandiant’s M-Trends 2026 report, grounded in more than 500,000 hours of frontline investigations, found that voice phishing now accounts for 11 percent of confirmed initial access vectors, making it the second-most common after software exploits. In cloud environments specifically, vishing rose to 23 percent of initial access events: the single most common cloud intrusion vector. Email phishing, by contrast, has fallen to just 6 percent of overall intrusions. Healthcare and technology, two sectors with deep Canadian roots, are named explicitly in Okta’s advisory as targets.
Verizon’s 2026 Data Breach Investigations Report reinforces the shift: phone-based social engineering now succeeds 40 percent more often than email-based attacks, and 41 percent of social engineering breaches in 2026 used non-email vectors. The threat has outgrown the inbox.
What This Means for Security Awareness in Canada
Most security awareness programs for Canadian organizations are built around email threats. They run simulated phishing campaigns, measure click rates, and trigger training when someone fails a lure. That model has real value for organisations building a structured program from the ground up. But it creates a gap that O-UNC-066 exploits directly: an employee who has never failed a training email may still take a well-crafted phone call and follow the attacker’s instructions step by step, handing over credentials and completing MFA enrollment on a fraudulent page.
In our work with mid-market Canadian enterprises, we consistently see security awareness programs that exist on paper but never reach the front-line employees who actually face the attacks. The gap between policy and practice is where incidents like this one are born.
Closing that gap means managing human risk across every communication channel your employees actually use. For vishing specifically, the core behaviour to build is a practised reflex: any unsolicited instruction to enrol a new credential or change an account setting is a verification-first situation, regardless of how credible the caller sounds. No legitimate IT protocol requires an employee to follow a link immediately during a phone call.
One Step to Take This Week
Ask your security awareness provider whether their program includes any voice-based scenarios. If not, raise it as a gap, and in the meantime brief every team on the passkey pretext: a caller from IT who asks you to immediately follow a link and register a new passkey is not following any legitimate IT process. Publish a direct number employees can call to verify any unexpected security request. That one step is the difference between a close call and a 72-hour extortion deadline.