Health Sector Faces Surge of ShinyHunters Data Theft via SSO Breaches

Health-ISAC warns that ShinyHunters are increasingly targeting healthcare by chaining supply-chain and identity attacks to gain access to cloud services through compromised SSO (Okta, Microsoft Entra, Google). Attackers use live voice phishing (vishing) to persuade employees or helpdesk staff to reset credentials or MFA, enabling rapid exfiltration from connected SaaS apps like Salesforce, Microsoft 365 and SharePoint. The advisory urges breaking the attack chain with out-of-band verification for resets, phishing-resistant MFA (FIDO2/WebAuthn), disabling SMS/voice OTP, treating SSO as Tier 0, centralizing SaaS logs, restricting API tokens, and rapid session revocation. Incidents have involved organizations such as Medtronic, DentaQuest, iRhythm, and OneMedical, and healthcare entities should focus on containment and strengthening controls over the next 30–60 days.
Reading Insights
1
5
5 min
vs 6 min read
89%
1,057 → 116 words
Want the full story? Read the original article
Read on BleepingComputer