Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

Healthcare

Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters.

ShinyHunters is an extortion gang that primarily conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks,

Over the past two years, the threat actors have become notorious for conducting numerous supply chain attacks on third-party integration partners. These breaches give them access to OAuth tokens that are used to integrate with SaaS providers like Salesforce and Snowflake.

image

The threat actors are known for identity attacks, where they target employees through social engineering, including vishing and phishing, to compromise corporate single-sign-on accounts. Once they gain access to an account, they log in to an organization’s Okta, Microsoft Entra, or Google SSO dashboard, which acts as a centralized hub listing all SaaS applications the user has permission to access.

Example Microsoft Entra SSO dashboard
Example Microsoft Entra SSO dashboard

These applications include Salesforce, a primary target of ShinyHunters, Microsoft 365, SharePoint, DocuSign, Slack, Atlassian, Dropbox, Google Drive, and many other internal and third-party platforms.

For threat actors focused on data theft and extortion, the SSO dashboard becomes a springboard to a company’s cloud data, allowing them to access multiple services from a single compromised account.

Hardening helpdesk and SSO security

According to a July 24 advisory, ShinyHunters attacks follow a chain that begins with voice phishing (vishing) to manipulate employees or helpdesk personnel into resetting passwords, changing multifactor authentication methods, or enrolling new devices.

BleepingComputer previously reported that ShinyHunters is using custom phishing kits built for voice-based social engineering (vishing) attacks.

These phishing kits are designed for live interaction with targeted employees via voice calls, allowing attackers to change content and display authentication dialogs in real time as a call progresses.

A C2 panel allowing real-time control of authentication flows
A C2 panel allowing real-time control of authentication flows
Source: Okta

Once an account is breached, the attackers use it to access connected SaaS platforms, where they rapidly steal data that can be used for extortion.

“SSO is the control plane, and ShinyHunters’ leverage is created through data theft at cloud scale,” Health-ISAC warned.

The advisory does not identify affected healthcare organizations, disclose how many incidents have been observed, or provide a timeframe for the reported increase.

However, BleepingComputer is aware of recent ShinyHunters attacks at healthcare and medtech companies, including MedtronicDentaQuest, iRhythm, and OneMedical.

Health-ISAC said that in recent incident reporting, ShinyHunters claimed it successfully vished multiple employees, compromised a Microsoft Entra SSO account, and stole data from Microsoft 365, SharePoint, and other enterprise platforms.

However, the organization cautioned that not every data theft claim has been verified, and defenders should instead focus on the attack pattern of using compromised SSO identities to access and exfiltrate data from connected cloud services.

Health-ISAC says the most important defensive step is breaking the attack chain between the initial vishing call and the takeover of an SSO account.

Organizations are advised to require out-of-band identity verification for password resets, MFA resets, and device re-enrollment requests.

This can include calling users back using a previously verified phone number and requiring manager approval for privileged accounts.

The advisory also recommends helpdesk personnel follow a “no same-call” policy that prevents resets during the same inbound call. Instead, reset requests should require a support ticket and a verified callback before any changes are made.

Additional verification should be required when changes are requested for executives, IT administrators, security personnel, finance employees, and other high-risk users.

Healthcare organizations should also deploy phishing-resistant MFA, such as FIDO2 or WebAuthn security keys, for administrators, helpdesk personnel, executives, and other high-risk groups.

SMS and voice-based authentication should be disabled or tightly restricted. At the same time, registering new MFA factors should require additional controls, such as a managed device or a conditional access policy.

Health-ISAC also recommends treating SSO systems as “Tier 0,” which represent the most critical assets in an organization.

This includes requiring MFA and compliant devices when accessing sensitive cloud services, blocking legacy authentication, detecting sessions with improbable geographic changes, and limiting administrative portals to managed devices.

Detecting cloud data theft

Health-ISAC recommends centralizing identity and SaaS audit logs and monitoring for signs of account takeover and large-scale data access, including new MFA registrations, newly enrolled devices, suspicious OAuth grants, unusual API activity, and bulk file downloads.

Organizations should also restrict API tokens and third-party integrations, require approval for access to sensitive data, and ensure incident response teams can quickly revoke active sessions, reset credentials, and turn off malicious OAuth applications.

Over the next 30 to 60 days, healthcare organizations are urged to prioritize phishing-resistant MFA for high-risk users, strengthen helpdesk reset procedures, enforce conditional access policies, and test their ability to contain compromised cloud accounts.


article image

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Read More
Lawrence Abrams

Latest

This Is The Most Immediate Difference Of A Mike McCarthy Practice

Throughout the next three weeks of Pittsburgh Steelers’ training camp, the team will have plenty of points of emphasis. Situational football that focuses on two-minute, like it did Wednesday, first down, goal line, and everything in between. Each day will feel a little different and have its own install and goal. One thing Mike McCarthy

Pittman’s Pocket: HBCU True Freshman All-American List Announced on July 30th “JUICE DAY” In Memory of OJ Murdock

Pittman’s Pocket: HBCU True Freshman All-American List Announced on July 30th “JUICE DAY” In Memory of OJ Murdock On July 30th, Pittman’s Pocket HBCU True Freshman All-American will honor the legacy of Orenthal “O.J.” Murdock by recognizing this day as “JUICE DAY.” This day is dedicated to remembering a talented football player, a Tampa community

Dave Richard’s ultimate step-by-step guide for drafting running backs in your 2026 Fantasy Football leagues

Your desire to draft running backs will come down to how you feel about the wide receiver position and how badly you want to lean into NFL trends. Wide receivers have become top-heavy in Fantasy, meaning there are very few who are viewed as high-target, high-volume, high-touchdown-capable players. There are significantly more running backs than

Saints star WR sits out of team drills on day one of practice

Although training camp is back and the New Orleans Saints are finally on the field again, the business side of football always tends to creep in. While most were worried about rookie Jordyn Tyson’s availability for drills, which turned out to be full participation, maybe some attention should have been put on Chris Olave’s contract.

Newsletter

Don't miss

This Is The Most Immediate Difference Of A Mike McCarthy Practice

Throughout the next three weeks of Pittsburgh Steelers’ training camp, the team will have plenty of points of emphasis. Situational football that focuses on two-minute, like it did Wednesday, first down, goal line, and everything in between. Each day will feel a little different and have its own install and goal. One thing Mike McCarthy

Pittman’s Pocket: HBCU True Freshman All-American List Announced on July 30th “JUICE DAY” In Memory of OJ Murdock

Pittman’s Pocket: HBCU True Freshman All-American List Announced on July 30th “JUICE DAY” In Memory of OJ Murdock On July 30th, Pittman’s Pocket HBCU True Freshman All-American will honor the legacy of Orenthal “O.J.” Murdock by recognizing this day as “JUICE DAY.” This day is dedicated to remembering a talented football player, a Tampa community

Dave Richard’s ultimate step-by-step guide for drafting running backs in your 2026 Fantasy Football leagues

Your desire to draft running backs will come down to how you feel about the wide receiver position and how badly you want to lean into NFL trends. Wide receivers have become top-heavy in Fantasy, meaning there are very few who are viewed as high-target, high-volume, high-touchdown-capable players. There are significantly more running backs than

Saints star WR sits out of team drills on day one of practice

Although training camp is back and the New Orleans Saints are finally on the field again, the business side of football always tends to creep in. While most were worried about rookie Jordyn Tyson’s availability for drills, which turned out to be full participation, maybe some attention should have been put on Chris Olave’s contract.

Saints 53-man roster prediction: Pre-training camp

The New Orleans Saints begin training camp this week, which means football is back. Of course, it’s not yet game time, but fans and analysts are going to finally get some clarification on roster battles, and for the Saints, there are plenty to pay attention to. As a result, a 53-man roster prediction may look

‘Sabah is open for business’: Hajiji courts investors with promise of sustainable growth, carbon‑negative credentials

Sabah is pitching itself as an Asia-Pacific hub for impact investing, betting that its forests, biodiversity and natural resources can become drivers of economic growth as it seeks private capital for sustainable development. — Picture by Firdaus Latif By Julia Chan First Published: Monday, 13 Jul 2026 11:44 AM MYT KOTA KINABALU, July 13 —

Want Your Business to Be Seen Everywhere? Meet Tonia Ryan, Creator of Fix Your Search

Some people are good at their jobs. Then there is Tonia Ryan, who has turned “getting found online” into something close to magic. She is the creator of Fix Your Search, and if you have ever wondered why some businesses pop up everywhere while others seem invisible...

Grey Business processes $61 million as stablecoins dominate payments

Grey Business enables startups and SMEs to open US Dollar (USD) corporate accounts, send and receive international payments, convert currencies, and transact using stablecoins such as USDC and USDT...