Back to feed
Dev.to
Dev.to
7/30/2026
The original headline is: "Health-ISAC warns of ShinyHunters vishing attacks targeting healthcare SSO and SaaS data"

The original headline is: "Health-ISAC warns of ShinyHunters vishing attacks targeting healthcare SSO and SaaS data"

Original: ShinyHunters: Breaking Help Desks via Vishing and Bulk Stealing SaaS via SSO

Short summary

Health-ISAC warns that ShinyHunters is actively targeting healthcare organizations through vishing attacks on help desks to hijack SSO accounts. Attackers manipulate users and help desk staff over the phone to reset passwords, remove MFA, and register new devices, then move laterally across M365, SharePoint, Salesforce, and other SaaS apps to steal bulk data. Mitigations include callback verification, FIDO2/WebAuthn enforcement, mandatory step-up authentication, and immediate session revocation.

  • Attackers use vishing to trick help desks into resetting MFA and registering attacker-controlled devices
  • Compromised SSO accounts enable lateral movement across M365, SharePoint, Salesforce, and other SaaS apps
  • Key mitigations: no same-call changes, callback verification, FIDO2/WebAuthn, and SaaS token revocation

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more