ShinyHunters Targets Healthcare via Vishing and SSO Hijacking, Health-ISAC Warns
Health-ISAC issued a warning on July 29, 2026, about escalating data theft attacks by the threat group ShinyHunters, which is increasingly targeting healthcare organizations. The group uses vishing — voice-based social engineering — to impersonate employees or IT staff and manipulate help desks into resetting passwords, removing MFA, and registering attacker-controlled devices. Once they gain control of an SSO identity provider such as Microsoft Entra ID, Okta, or Google SSO, attackers move laterally across connected SaaS platforms including Microsoft 365, SharePoint, Salesforce, and Slack to steal data in bulk. The attacks leave minimal endpoint traces, making detection difficult without correlating identity provider logs with SaaS audit trails. Health-ISAC recommends enforcing FIDO2/WebAuthn authentication, requiring manager approval for high-risk account changes, and prohibiting authentication changes during the same support call.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in