Dev.to
7/30/2026

The original headline is: "Health-ISAC warns of ShinyHunters vishing attacks targeting healthcare SSO and SaaS data"
Original: ShinyHunters: Breaking Help Desks via Vishing and Bulk Stealing SaaS via SSO
Short summary
Health-ISAC warns that ShinyHunters is actively targeting healthcare organizations through vishing attacks on help desks to hijack SSO accounts. Attackers manipulate users and help desk staff over the phone to reset passwords, remove MFA, and register new devices, then move laterally across M365, SharePoint, Salesforce, and other SaaS apps to steal bulk data. Mitigations include callback verification, FIDO2/WebAuthn enforcement, mandatory step-up authentication, and immediate session revocation.
- •Attackers use vishing to trick help desks into resetting MFA and registering attacker-controlled devices
- •Compromised SSO accounts enable lateral movement across M365, SharePoint, Salesforce, and other SaaS apps
- •Key mitigations: no same-call changes, callback verification, FIDO2/WebAuthn, and SaaS token revocation
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



