Health-ISAC, the cybersecurity information-sharing organization for the health sector, has warned member organizations of a sharp increase in successful data theft attacks by the ShinyHunters extortion group targeting healthcare and medical technology companies.
According to a July 24 advisory, ShinyHunters has been conducting sophisticated vishing campaigns that manipulate employees and helpdesk personnel into resetting passwords, changing multifactor authentication methods, or enrolling new devices. Once an account is compromised, the attackers use it to access a company’s Okta, Microsoft Entra, or Google SSO dashboard, which researchers describe as a springboard to multiple cloud platforms containing sensitive patient and corporate data.
The threat actors have developed custom phishing kits built specifically for voice-based social engineering. These kits allow attackers to change displayed content and authentication dialogs in real time during a live phone call with the targeted employee. Health-ISAC noted that ShinyHunters has successfully vished multiple healthcare employees in recent incidents, compromising Microsoft Entra SSO accounts and stealing data from Microsoft 365, SharePoint, and other enterprise platforms.
BleepingComputer has confirmed recent ShinyHunters attacks at healthcare and medtech companies including Medtronic, DentaQuest, iRhythm, and One Medical. Health-ISAC advised that the most important defensive step is breaking the attack chain between the initial vishing call and the takeover of an SSO account, recommending vishing simulations for new hires and remote workers along with published SSO takeover indicators for IT staff.
