[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$forx8PmyyIulw_Dp-r7OGbipje9g9Y53bBsbaIBIlv9A":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"1429d7c0-bc51-4ee0-bb70-eacaa2c525ac","Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare","health-isac-warns-of-rising-shinyhunters-data-theft-attacks-on-healthcare-377d82","Health-ISAC is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters, which are using social engineering to compromise single sign-on accounts and steal data from cloud services. [...]","Health-ISAC is alerting healthcare and medical technology organizations to a rise in ShinyHunters attacks. The threat group uses social engineering, including vishing, to compromise single sign-on (SSO) accounts, gaining access to cloud services like Salesforce and Microsoft 365 for data theft and extortion. Organizations are advised to implement out-of-band identity verification for sensitive requests to break the attack chain.","Health-ISAC warns of increased ShinyHunters attacks targeting healthcare SSO accounts.","Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare By Lawrence Abrams July 29, 2026 01:54 PM 0 Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters. ShinyHunters is an extortion gang that primarily conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks, Over the past two years, the threat actors have become notorious for conducting numerous supply chain attacks on third-party integration partners. These breaches give them access to OAuth tokens that are used to integrate with SaaS providers like Salesforce and Snowflake. The threat actors are known for identity attacks, where they target employees through social engineering, including vishing and phishing, to compromise corporate single-sign-on accounts. Once they gain access to an account, they log in to an organization's Okta, Microsoft Entra, or Google SSO dashboard, which acts as a centralized hub listing all SaaS applications the user has permission to access. Example Microsoft Entra SSO dashboard These applications include Salesforce, a primary target of ShinyHunters, Microsoft 365, SharePoint, DocuSign, Slack, Atlassian, Dropbox, Google Drive, and many other internal and third-party platforms. For threat actors focused on data theft and extortion, the SSO dashboard becomes a springboard to a company's cloud data, allowing them to access multiple services from a single compromised account. Hardening helpdesk and SSO security According to a July 24 advisory, ShinyHunters attacks follow a chain that begins with voice phishing (vishing) to manipulate employees or helpdesk personnel into resetting passwords, changing multifactor authentication methods, or enrolling new devices. BleepingComputer previously reported that ShinyHunters is using custom phishing kits built for voice-based social engineering (vishing) attacks. These phishing kits are designed for live interaction with targeted employees via voice calls, allowing attackers to change content and display authentication dialogs in real time as a call progresses. A C2 panel allowing real-time control of authentication flowsSource: Okta Once an account is breached, the attackers use it to access connected SaaS platforms, where they rapidly steal data that can be used for extortion. \"SSO is the control plane, and ShinyHunters' leverage is created through data theft at cloud scale,\" Health-ISAC warned. The advisory does not identify affected healthcare organizations, disclose how many incidents have been observed, or provide a timeframe for the reported increase. However, BleepingComputer is aware of recent ShinyHunters attacks at healthcare and medtech companies, including Medtronic, DentaQuest, iRhythm, and OneMedical. Health-ISAC said that in recent incident reporting, ShinyHunters claimed it successfully vished multiple employees, compromised a Microsoft Entra SSO account, and stole data from Microsoft 365, SharePoint, and other enterprise platforms. However, the organization cautioned that not every data theft claim has been verified, and defenders should instead focus on the attack pattern of using compromised SSO identities to access and exfiltrate data from connected cloud services. Health-ISAC says the most important defensive step is breaking the attack chain between the initial vishing call and the takeover of an SSO account. Organizations are advised to require out-of-band identity verification for password resets, MFA resets, and device re-enrollment requests. This can include calling users back using a previously verified phone number and requiring manager approval for privileged accounts. The advisory also recommends helpdesk personnel follow a \"no same-call\" policy that prevents resets during the same inbound call. Instead, reset requests should require a support ticket and a verified callback before any changes are made. Additional verification should be required when changes are requested for executives, IT administrators, security personnel, finance employees, and other high-risk users. Healthcare organizations should also deploy phishing-resistant MFA, such as FIDO2 or WebAuthn security keys, for administrators, helpdesk personnel, executives, and other high-risk groups. SMS and voice-based authentication should be disabled or tightly restricted. At the same time, registering new MFA factors should require additional controls, such as a managed device or a conditional access policy. Health-ISAC also recommends treating SSO systems as \"Tier 0,\" which represent the most critical assets in an organization. This includes requiring MFA and compliant devices when accessing sensitive cloud services, blocking legacy authentication, detecting sessions with improbable geographic changes, and limiting administrative portals to managed devices. Detecting cloud data theft Health-ISAC recommends centralizing identity and SaaS audit logs and monitoring for signs of account takeover and large-scale data access, including new MFA registrations, newly enrolled devices, suspicious OAuth grants, unusual API activity, and bulk file downloads. Organizations should also restrict API tokens and third-party integrations, require approval for access to sensitive data, and ensure incident response teams can quickly revoke active sessions, reset credentials, and turn off malicious OAuth applications. Over the next 30 to 60 days, healthcare organizations are urged to prioritize phishing-resistant MFA for high-risk users, strengthen helpdesk reset procedures, enforce conditional access policies, and test their ability to contain compromised cloud accounts. Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper Related Articles: Ernst & Young data breach claimed by ShinyHunters extortion gangDentaQuest data breach exposed info of 2.6 million accountsShinyHunters data leaks fuel $2,000 sextortion email scamAbbott probes two cyber incidents amid extortion claimsMedtronic notifies customers impacted by ShinyHunters data breach","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhealth-isac-warns-of-rising-shinyhunters-data-theft-attacks-on-healthcare\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2022\u002F08\u002F22\u002Fhealthcare-cyber.jpg","2026-07-29T17:54:05+00:00","2026-07-29T18:00:19.581069+00:00",8,[18,21,24,26,28,30],{"name":19,"type":20},"ShinyHunters","threat_actor",{"name":22,"type":23},"Salesforce","product",{"name":25,"type":23},"Snowflake",{"name":27,"type":23},"Okta",{"name":29,"type":23},"Microsoft Entra",{"name":31,"type":23},"Google SSO","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":32,"icon":34,"name":35,"slug":36},null,"Threat Intelligence","threat-intelligence",[38,43,48,53],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":49},{"id":50,"icon":34,"name":51,"slug":52},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":54},{"id":32,"icon":34,"name":35,"slug":36},[]]