CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6291

As cited

Copy frozen at (site build).

threat intel

Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks

Health-ISAC has alerted healthcare and medtech organizations to escalating attacks by ShinyHunters, a threat group that uses voice-based social engineering to compromise cloud identity and access management systems and exfiltrate sensitive data. The group targets cloud SaaS platforms like Microsoft 365, Okta, and Salesforce after gaining initial access through vishing calls that trick employees into resetting passwords or multifactor authentication (MFA), then demands ransom to prevent leaked data publication. Health-ISAC recommends hardening identity workflows with out-of-band verification, implementing phishing-resistant MFA for high-risk users, treating single sign-on (SSO) systems as critical assets, and centralizing logs into security information and event management (SIEM) systems to detect account compromise and unusual data access patterns.

Why it matters: Healthcare and medtech organizations face immediate extortion risk from ShinyHunters vishing campaigns targeting helpdesk staff and privileged users; implementing out-of-band identity verification and phishing-resistant MFA within 30 to 60 days can break the attack chain before data loss occurs.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks

Health-ISAC has alerted healthcare and medtech organizations to escalating attacks by ShinyHunters, a threat group that uses voice-based social engineering to compromise cloud identity and access management systems and exfiltrate sensitive data. The group targets cloud SaaS platforms like Microsoft 365, Okta, and Salesforce after gaining initial access through vishing calls that trick employees into resetting passwords or multifactor authentication (MFA), then demands ransom to prevent leaked data publication. Health-ISAC recommends hardening identity workflows with out-of-band verification, implementing phishing-resistant MFA for high-risk users, treating single sign-on (SSO) systems as critical assets, and centralizing logs into security information and event management (SIEM) systems to detect account compromise and unusual data access patterns.

Why it matters: Healthcare and medtech organizations face immediate extortion risk from ShinyHunters vishing campaigns targeting helpdesk staff and privileged users; implementing out-of-band identity verification and phishing-resistant MFA within 30 to 60 days can break the attack chain before data loss occurs.

VendorsMicrosoftGoogleOktaSalesforce
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary