A new threat actor is bypassing traditional defenses by using voice phishing and native Microsoft 365 features to exfiltrate corporate data at unprecedented speeds.
The digital battlefield is undergoing a fundamental shift as sophisticated extortion clusters move away from traditional malware toward identity-centric warfare. The emergence of the ‘Pink’ extortion group, identified by Palo Alto Networks’ Unit 42 as CL-CRI-1147, represents a significant escalation. Operating with a clinical efficiency that challenges American digital sovereignty, this group focuses on the rapid exfiltration of cloud-resident intellectual property rather than simple encryption.
Pink’s operational methodology begins with highly targeted ‘vishing’ or voice phishing. Attackers impersonate internal IT help desk personnel to manipulate employees into visiting credential-harvesting domains like passkeyaddcom and passkeydeploy.com. This human-centric breach allows the group to hijack active Microsoft 365 sessions, effectively neutralizing Multi-Factor Authentication (MFA). By assuming the identity of a legitimate user, the attackers gain a foothold indistinguishable from authorized access in many legacy monitoring systems.
Once inside the Microsoft 365 environment, Pink demonstrates a mastery of ‘living off the land.’ Rather than deploying detectable ransomware payloads, the group utilizes built-in Microsoft automation and export features to siphon data from OneDrive and SharePoint. Reports indicate that Pink can exfiltrate massive volumes of sensitive corporate data within minutes. This speed is facilitated by the group’s use of legitimate OAuth applications and administrative APIs, allowing them to maintain persistence while remaining hidden within the noise of daily cloud operations.
Technical analysis from Gurucul underscores the sophistication of these intrusions. The group utilizes fileless techniques that execute entirely in memory, checking for sandboxes and hiding within legitimate system paths to evade Endpoint Detection and Response (EDR) solutions. Because the activity occurs within the cloud tenant rather than on a physical workstation, traditional antivirus software is often blind to the theft. This method exploits the inherent trust models of SaaS platforms, turning productivity tools into weapons for data exfiltration.
The psychological dimension of Pink’s campaign is equally aggressive. After securing the data, the group launches extortion demands directly from the victim’s own Outlook and Teams accounts. This tactic ensures the message is read and amplifies the sense of total compromise. With a strict 72-hour payment window, the group leverages the threat of public exposure on their dedicated leak site, which launched May 31, 2026. This rapid-fire cycle is designed to bypass board-level deliberations and force immediate financial capitulation.
This development comes as global semiconductor billings rise 14% year-over-year, driven by AI investment. While the U.S. celebrates technical milestones like the X-59 supersonic flight and the Antares modular reactor reaching criticality, the underlying digital infrastructure remains exposed. The Pink group’s ability to weaponize cloud tools suggests the ‘New Cold War’ will be won or lost in the identity layer.
Federal agencies have yet to issue a specific joint advisory for the Pink cluster, though existing guidance on cloud forensics remains the primary defense. The group’s link to the broader ‘Com’ network suggests a deep pool of shared intelligence. For American enterprises, digital sovereignty cannot be maintained through software alone; it requires a fundamental hardening of the human and identity layers against an adversary that no longer needs malware to succeed.

