CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Health-ISAC warns ShinyHunters targets health sector with vishing, credential theft and MFA bypass tactics

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6828

As cited

Copy frozen at (site build).

identity access

Health-ISAC warns ShinyHunters targets health sector with vishing, credential theft and MFA bypass tactics

Health-ISAC reports that the ShinyHunters cybercrime group is conducting targeted vishing campaigns against healthcare organizations to harvest credentials and bypass multifactor authentication (MFA). After obtaining credentials, attackers use reverse-proxy phishing techniques to capture active MFA tokens and gain access to cloud services including Microsoft 365, SharePoint, and Salesforce to exfiltrate data for extortion. The group registers medical-themed domains with corporate name prefixes to impersonate legitimate login portals and pressure victims through aggressive calls and voicemails.

Why it matters: Healthcare practitioners and IT teams should immediately implement phishing-resistant MFA (FIDO2/WebAuthn), restrict SaaS access to managed devices, block .claim and .claims domains, and train staff on vishing tactics, as ShinyHunters is actively exploiting identity and SaaS platforms as an extortion vector.

VendorsMicrosoftSalesforce
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary