Skip to content
ShinyHunters Vishing Campaign Targets Okta SSO and SaaS Platforms

ShinyHunters Vishing Campaign Targets Okta SSO and SaaS Platforms

First seen 27 Sep 2026, 10:22 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 09:33 UTC
  • •ShinyHunters employs voice phishing to steal SSO credentials and bypass MFA.
  • •Attackers impersonate IT staff and use real-time phishing kits for credential harvesting.
  • •The campaign targets SaaS platforms, particularly in the healthcare sector, with a focus on extortion.

A voice phishing campaign attributed to the ShinyHunters group is actively targeting organizations using Okta SSO and other SaaS platforms. The attackers impersonate IT staff to convince employees to provide their SSO credentials and MFA codes through counterfeit login portals. Once the attackers gain access, they can register their devices, bypass MFA protections, and exfiltrate sensitive data for extortion. This campaign does not exploit software vulnerabilities but relies on advanced social engineering techniques. Mandiant has linked this activity to multiple clusters, including UNC6661 and UNC6671, and noted that it has been ongoing since early January 2026. The healthcare sector has been particularly affected, with reports of aggressive tactics and impersonation of medical staff. Organizations are advised to enhance their MFA methods and conduct regular training to mitigate risks. The campaign represents a significant shift in threat vectors, emphasizing the need for phishing-resistant authentication methods.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-01-05
Vishing campaign begins
Mandiant reports the start of sophisticated vishing operations targeting enterprise employees.
csirt.ncc.gov.ng
2026-09-27
ShinyHunters claims credit
ShinyHunters claims responsibility for multiple voice phishing attacks targeting Okta SSO credentials.
infosightinc.com
2026-09-27
Healthcare sector targeted
Health-ISAC reports a surge in vishing attacks specifically targeting healthcare organizations.
crbcnews.com

More articles in this cluster (4)

Following this threat?

Track Unc6240 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed