ShinyHunters Vishing Campaign Targets Okta SSO and SaaS Platforms
Article Content
- •ShinyHunters employs voice phishing to steal SSO credentials and bypass MFA.
- •Attackers impersonate IT staff and use real-time phishing kits for credential harvesting.
- •The campaign targets SaaS platforms, particularly in the healthcare sector, with a focus on extortion.
A voice phishing campaign attributed to the ShinyHunters group is actively targeting organizations using Okta SSO and other SaaS platforms. The attackers impersonate IT staff to convince employees to provide their SSO credentials and MFA codes through counterfeit login portals. Once the attackers gain access, they can register their devices, bypass MFA protections, and exfiltrate sensitive data for extortion. This campaign does not exploit software vulnerabilities but relies on advanced social engineering techniques. Mandiant has linked this activity to multiple clusters, including UNC6661 and UNC6671, and noted that it has been ongoing since early January 2026. The healthcare sector has been particularly affected, with reports of aggressive tactics and impersonation of medical staff. Organizations are advised to enhance their MFA methods and conduct regular training to mitigate risks. The campaign represents a significant shift in threat vectors, emphasizing the need for phishing-resistant authentication methods.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Unc6240 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…