ShinyHunters Intensifies Attacks on Healthcare Sector Via SSO Compromises
The **Health-ISAC** is issuing a critical warning to healthcare and medical technology organizations regarding a significant surge in successful attacks by the **ShinyHunters** extortion gang. These threat actors are leveraging sophisticated social engineering and identity attacks to breach cloud SaaS and storage platforms, primarily targeting Single Sign-On (SSO) accounts to facilitate extensive data theft.

**ShinyHunters**, a notorious extortion group, has escalated its attacks on the healthcare sector. The gang is known for supply chain and identity-based breaches, primarily targeting cloud SaaS and storage platforms to exfiltrate sensitive data.
Over the past two years, **ShinyHunters** has gained notoriety for numerous supply chain attacks on third-party integration partners. These breaches often yield **OAuth** tokens, which are then exploited to access SaaS providers such as **Salesforce** and **Snowflake**.
### The Identity Attack Vector
The group's modus operandi frequently involves identity attacks, employing social engineering tactics like vishing and phishing. Their objective is to compromise corporate Single Sign-On (SSO) accounts. Once an account is breached, the attackers gain access to dashboards like **Okta**, **Microsoft Entra**, or **Google SSO**, which serve as central hubs listing all SaaS applications accessible to the compromised user.

These accessible applications often include **Salesforce**, **Microsoft 365**, **SharePoint**, **DocuSign**, **Slack**, **Atlassian**, **Dropbox**, and **Google Drive**, among others. For threat actors focused on data theft and extortion, the SSO dashboard becomes a critical springboard, enabling access to a company's cloud data from a single compromised account.
### Hardening Helpdesk and SSO Security
According to a **Health-ISAC** advisory issued on July 24, **ShinyHunters** attacks typically begin with voice phishing (vishing). This technique is used to manipulate employees or helpdesk personnel into resetting passwords, altering multi-factor authentication (MFA) methods, or enrolling new devices.
Previously reported, **ShinyHunters** utilizes custom phishing kits specifically designed for vishing. These kits facilitate real-time interaction with targeted employees during voice calls, allowing attackers to dynamically change content and display authentication dialogs as the call progresses.

Once an account is compromised, attackers swiftly leverage it to access connected SaaS platforms, rapidly stealing data for extortion purposes. **Health-ISAC** warns that "SSO is the control plane, and **ShinyHunters**' leverage is created through data theft at cloud scale."
While the advisory does not specify affected healthcare organizations, the number of incidents, or a precise timeframe for the reported increase, **Medtronic**, **DentaQuest**, **iRhythm**, and **OneMedical** have recently been impacted by **ShinyHunters** breaches.
Recent incident reports indicate **ShinyHunters** successfully vished multiple employees, compromised a **Microsoft Entra** SSO account, and exfiltrated data from **Microsoft 365**, **SharePoint**, and other enterprise platforms. **Health-ISAC** emphasizes focusing on the attack pattern of using compromised SSO identities to access and exfiltrate data from connected cloud services, rather than verifying every data theft claim.
### Mitigating the Attack Chain
The most critical defensive measure, according to **Health-ISAC**, is to disrupt the attack chain between the initial vishing call and the SSO account takeover. Organizations are strongly advised to:
* **Require Out-of-Band Identity Verification:** Implement this for password resets, MFA resets, and device re-enrollment requests. This could involve calling users back on a pre-verified phone number and requiring manager approval for privileged accounts.
* **Enforce a "No Same-Call" Policy:** Helpdesk personnel should avoid resetting during the same inbound call. Instead, reset requests should necessitate a support ticket and a verified callback.
* **Demand Additional Verification:** Especially for executives, IT administrators, security personnel, finance employees, and other high-risk users.
* **Deploy Phishing-Resistant MFA:** Utilize **FIDO2** or **WebAuthn** security keys for administrators, helpdesk personnel, executives, and other high-risk groups. SMS and voice-based authentication should be disabled or tightly restricted, and new MFA factor registrations should require additional controls, such as a managed device or a conditional access policy.
* **Treat SSO Systems as "Tier 0" Assets:** This means requiring MFA and compliant devices for accessing sensitive cloud services, blocking legacy authentication, detecting sessions with improbable geographic changes, and limiting administrative portals to managed devices.
### Detecting Cloud Data Theft
**Health-ISAC** recommends centralizing identity and SaaS audit logs. Organizations should actively monitor for signs of account takeover and large-scale data access, including new MFA registrations, newly enrolled devices, suspicious **OAuth** grants, unusual API activity, and bulk file downloads.
Furthermore, organizations should restrict API tokens and third-party integrations, require approval for access to sensitive data, and ensure incident response teams are equipped to quickly revoke active sessions, reset credentials, and disable malicious **OAuth** applications.
Over the next 30 to 60 days, healthcare organizations should prioritize implementing phishing-resistant MFA for high-risk users, strengthening helpdesk reset procedures, enforcing conditional access policies, and thoroughly testing their ability to contain compromised cloud accounts. This proactive approach is essential to safeguard against the evolving tactics of groups like **ShinyHunters**.