top of page
perceptive_background_267k.jpg

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

Published:

29 juli 2026 om 19:54:05

Alert date:

29 juli 2026 om 20:02:14

Source:

bleepingcomputer.com

Click to open the original link from this advisory

Identity & Access, Data Breach & Exfiltration, Cloud & Virtualization, Critical Infrastructure, Supply Chain & Dependencies

Health-ISAC has issued a warning to healthcare and medical technology organizations about a rising number of successful cyberattacks conducted by the ShinyHunters threat group. The attackers are leveraging social engineering techniques to compromise single sign-on (SSO) accounts, enabling them to gain unauthorized access to cloud services and exfiltrate sensitive data. The healthcare sector is particularly vulnerable due to its reliance on cloud-based systems and SSO authentication. The campaign represents a significant escalation in ShinyHunters' targeting of the healthcare vertical. Organizations are urged to review their SSO configurations, enforce multi-factor authentication, and train staff on social engineering awareness. The advisory highlights the growing threat of identity-based attacks against critical healthcare infrastructure.

Technical details

ShinyHunters is an extortion gang conducting supply chain and identity attacks targeting cloud SaaS and storage platforms. Their attack chain begins with voice phishing (vishing) to manipulate employees or helpdesk personnel into resetting passwords, changing MFA methods, or enrolling new devices. They use custom phishing kits designed for live voice-based social engineering that allow attackers to dynamically change content and display authentication dialogs in real time during a call via a C2 panel. Once an SSO account is compromised (Okta, Microsoft Entra, or Google SSO), the attackers leverage the SSO dashboard as a centralized hub to access all connected SaaS applications, including Salesforce, Microsoft 365, SharePoint, DocuSign, Slack, Atlassian, Dropbox, and Google Drive. They also conduct supply chain attacks on third-party integration partners to obtain OAuth tokens used to integrate with SaaS providers like Salesforce and Snowflake. In recent confirmed incidents, ShinyHunters vished multiple employees, compromised Microsoft Entra SSO accounts, and exfiltrated data from Microsoft 365, SharePoint, and other enterprise platforms. Known affected healthcare/medtech victims include Medtronic, DentaQuest, iRhythm, and OneMedical.

Mitigation steps:

1. Break the attack chain between vishing and SSO account takeover by requiring out-of-band identity verification for all password resets, MFA resets, and device re-enrollment requests (e.g., call back using a previously verified phone number, require manager approval for privileged accounts). 2. Implement a 'no same-call' helpdesk policy — reset requests must be submitted via a support ticket and require a verified callback before any changes are made. 3. Apply additional verification requirements for high-risk users: executives, IT administrators, security personnel, and finance employees. 4. Deploy phishing-resistant MFA (FIDO2 or WebAuthn security keys) for admins, helpdesk, executives, and other high-risk groups. 5. Disable or tightly restrict SMS and voice-based authentication. Require a managed device or conditional access policy for registering new MFA factors. 6. Treat SSO systems as 'Tier 0' critical assets: require MFA and compliant devices for sensitive cloud service access, block legacy authentication, detect sessions with improbable geographic changes, and limit admin portals to managed devices. 7. Centralize identity and SaaS audit logs; monitor for new MFA registrations, newly enrolled devices, suspicious OAuth grants, unusual API activity, and bulk file downloads. 8. Restrict API tokens and third-party integrations; require approval for access to sensitive data. 9. Ensure incident response teams can quickly revoke active sessions, reset credentials, and disable malicious OAuth applications. 10. Over the next 30–60 days, prioritize phishing-resistant MFA for high-risk users, strengthen helpdesk reset procedures, enforce conditional access policies, and test the ability to contain compromised cloud accounts.

Affected products:

Okta SSO
Microsoft Entra (SSO/Identity)
Google SSO
Microsoft 365
SharePoint
Salesforce
Snowflake
DocuSign
Slack
Atlassian
Dropbox
Google Drive

Related links:

Related CVE's:

Related threat actors:

IOC's:

New MFA device or factor registrations on SSO accounts, Newly enrolled devices in SSO platforms, Suspicious OAuth application grants, Unusual or high-volume API activity, Bulk file downloads from cloud storage (SharePoint, Google Drive, Dropbox), Impossible travel / improbable geographic session changes in SSO logs, Inbound helpdesk calls requesting password or MFA resets, New third-party OAuth integrations with access to sensitive data

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page