Pink is a financially motivated data-extortion cluster that uses fake internal IT calls and tailored Microsoft Entra ID or Okta phishing sites to steal authentication material. Observed activity includes theft from SharePoint and OneDrive followed by extortion through compromised corporate communications, without evidence of file encryption.
Credential-driven extortion operation using voice phishing, tailored identity-provider lures, cloud-data theft, and pressure through compromised business communications.
Actor class
Data-extortion group
Motivation
Financial
Activity timeline
First observed
Early March 2026
Status
Active as of the reviewed date
Status as of
2026-08-17
Leak site live
2026-05-31
Attribution assessment
Facts
Likely connected to the broader Com cybercriminal ecosystem based on tradecraft similarities.
A likely rebrand relationship with Redact is tracked separately as an assessed relationship, not as an alias.
Pink's data-leak site claims that the group has no association with prior groups.
Operational playbook
Extortion deadline hours
72
Stages
Call employees while impersonating internal IT support.
Direct selected employees to a target-specific Entra ID or Okta phishing site.
Capture credentials and authentication responses through an operator-controlled kit.
Collect and exfiltrate cloud data from SharePoint and OneDrive.
Send extortion demands through compromised email or internal Teams messages.
Provide qTox and a Pink data-leak site as contact and pressure channels.
Initial access and identity targets
Methods
Voice phishing
Tailored spearphishing links
Internal IT impersonation
Identity Platforms
Microsoft Entra ID
Okta
Authentication Targets
Passwords
MFA number matching
Passkey recovery or registration workflows
Capabilities and evasion
Phishing Kits
Microsoft Entra ID live-panel kit
Operator-controlled Okta impersonation kit
Evasion
WebGL checks for virtualized graphics renderers
Headless-browser and automation artifact checks
Screen-size and timezone anomaly checks
ASN filtering for cloud, data-center, VPN, and proxy traffic
Human-interaction gates and hidden honeypot fields
Backend approval before a lure is revealed
Operator Control
Heartbeat telemetry and session tracking
Dynamic single-page application routing
Target-specific tenant branding
Live redirection between authentication stages
Credential exfiltration with sendBeacon and XMLHttpRequest fallback
Infrastructure patterns
Hosting Providers
Cloudflare
DDoS-Guard
Registrars
Tucows
Nicenic
Domain Patterns
{target_brand}.{keyword}passkey.com
{target_brand}.passkey{keyword}.com
Validation
Target-brand subdomains
Phishing-kit content observed in URLScan DOM captures
Communication and pressure channels
Channels
Compromised corporate email
Microsoft Teams
qTox
Pink data-leak site
Observed targeting
Targeting, not victimization. Observed brand lures indicate targeting intent and are not confirmation that an organization was compromised.
Healthcare and biotech20 · 26.7%
Technology and SaaS16 · 21.3%
Financial services16 · 21.3%
Professional services7 · 9.3%
Media and entertainment6 · 8%
Construction, infrastructure, and real estate5 · 6.7%
Aviation, logistics, and transportation3 · 4%
Consumer retail, energy, and food2 · 2.7%
Defender guidance
Measures
Train employees to verify unexpected internal IT calls through a separate trusted channel.
Prefer hardware-backed FIDO2 or WebAuthn over push-based MFA.
Monitor for anomalous sign-ins and unexpected authentication-method or passkey registrations.
Investigate target-branded subdomains on passkey-themed domains, while treating naming alone as a lead rather than attribution.
Activity timeline
A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.
Cataloged
Indicator1 indicator cataloged
Types: domain.
Cataloged
Indicator1 indicator cataloged
Types: domain.
Cataloged
Indicator34 indicators cataloged
Types: domain.
Cataloged
RelationshipRebrand of relationship with Redact
Pink is assessed as a likely rebrand of Redact. The assessment is shown as a relationship because it is not an exact-name equivalence.
Medium
Cataloged
IdentityTracking identifier: CL-CRI-1147
Reviewed identity mapping approved on this date.
Identity and attribution
Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.