Actor Profile

ShinyHunters is a financially motivated extortion gang specializing in data theft attacks against cloud SaaS and storage platforms. The group has gained notoriety over the past two years for conducting supply chain attacks on third-party integration partners to obtain OAuth tokens for services like Salesforce and Snowflake. ShinyHunters employs sophisticated social engineering tactics, including vishing (voice phishing) and phishing, to compromise corporate single-sign-on (SSO) accounts. Once inside SSO platforms such as Okta, Microsoft Entra, or Google SSO, the actors leverage centralized access to exfiltrate data from multiple connected cloud services for extortion purposes. The group uses custom phishing kits designed for real-time, voice-based social engineering that allow dynamic manipulation of authentication flows during live calls with victims.

TTPs (Tactics, Techniques, Procedures)

ShinyHunters employs a multi-stage attack chain beginning with voice phishing (vishing) to manipulate employees or helpdesk personnel into resetting passwords, changing MFA methods, or enrolling new devices (T1566.004 - Phishing: Spearphishing Voice). The group conducts supply chain attacks on third-party integration partners to obtain OAuth tokens (T1199 - Trusted Relationship, T1550.001 - Use Alternate Authentication Material: Application Access Token). Once credentials are compromised, attackers access SSO dashboards (T1078.004 - Valid Accounts: Cloud Accounts) to pivot to connected SaaS platforms including Salesforce, Microsoft 365, SharePoint, DocuSign, Slack, Atlassian, Dropbox, and Google Drive. Data exfiltration occurs at cloud scale through bulk downloads and API abuse (T1567.002 - Exfiltration Over Web Service: Exfiltration to Cloud Storage, T1213 - Data from Information Repositories). The group uses custom phishing kits with command-and-control panels that enable real-time manipulation of authentication dialogs during vishing calls.

Targets & Patterns

ShinyHunters is actively targeting healthcare and medical technology organizations, with Health-ISAC reporting an observed increase in successful attacks against the health sector. Known victims include Medtronic, DentaQuest, iRhythm, and OneMedical. The group targets employees with access to SSO systems, with particular focus on helpdesk personnel who can be manipulated into performing password resets and MFA changes. High-value targets include executives, IT administrators, security personnel, and finance employees who have elevated access to sensitive cloud services. The healthcare sector is attractive due to the sensitive nature of patient data and the sector's reliance on cloud SaaS platforms for operational functions. ShinyHunters' focus on supply chain partners and third-party integrations amplifies their reach across multiple organizations through compromised OAuth tokens and trusted relationships.

Historical Context

Over the past two years, ShinyHunters has become notorious for conducting numerous supply chain attacks on third-party integration partners, establishing a pattern of exploiting trusted relationships to gain access to OAuth tokens for major SaaS providers. Recent attacks demonstrate the group's continued focus on healthcare and medical technology sectors, with multiple confirmed breaches at prominent organizations including Medtronic, DentaQuest, iRhythm, and OneMedical. The Health-ISAC advisory issued on July 24, 2026, represents a formal warning to the healthcare sector about an observed increase in successful ShinyHunters campaigns. The group's evolution includes the development of sophisticated custom phishing kits specifically designed for real-time vishing operations, indicating increasing technical sophistication and operational maturity in their social engineering capabilities.

Defensive Recommendations

  • Implement phishing-resistant MFA (FIDO2 or WebAuthn security keys) for administrators, helpdesk personnel, executives, and high-risk users; disable SMS and voice-based authentication to prevent vishing-based MFA bypass (T1078.004, T1556)
  • Enforce out-of-band identity verification for all password resets, MFA changes, and device enrollments using verified callback numbers and manager approval for privileged accounts; implement a 'no same-call' helpdesk policy requiring support tickets and verified callbacks before changes
  • Treat SSO systems as Tier 0 critical assets with conditional access policies requiring MFA and compliant managed devices; block legacy authentication and detect sessions with improbable geographic changes (T1078.004)
  • Centralize identity and SaaS audit logs to monitor for account takeover indicators including new MFA registrations, newly enrolled devices, suspicious OAuth grants, unusual API activity, and bulk file downloads (T1213, T1567.002)
  • Restrict API tokens and third-party OAuth integrations; require approval workflows for access to sensitive data and ensure incident response teams can rapidly revoke active sessions, reset credentials, and disable malicious OAuth applications (T1550.001, T1199)