Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Sanctions Bill Would Give Trump Sweeping New Tariff Powers

    July 30, 2026

    Record Numbers of FOIA Public Document Requests Are in Limbo or Unfulfilled

    July 30, 2026

    It Looks Like Nothing Can Dent MAGA’s Support for ICE

    July 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Sanctions Bill Would Give Trump Sweeping New Tariff Powers
    • Record Numbers of FOIA Public Document Requests Are in Limbo or Unfulfilled
    • It Looks Like Nothing Can Dent MAGA’s Support for ICE
    • US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security
    • Microsoft Quietly Adds New Windows App That Wants to Scan Your Face
    • NASA Awards 2026 Innovative Technology Concepts
    • Conservation shouldn’t gamble with nonnative species introductions (commentary)
    • Shameful treatment of vulnerable families in heatwave | Extreme heat
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, July 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 29, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters.

    ShinyHunters is an extortion gang that primarily conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks,

    Over the past two years, the threat actors have become notorious for conducting numerous supply chain attacks on third-party integration partners. These breaches give them access to OAuth tokens that are used to integrate with SaaS providers like Salesforce and Snowflake.

    image

    The threat actors are known for identity attacks, where they target employees through social engineering, including vishing and phishing, to compromise corporate single-sign-on accounts. Once they gain access to an account, they log in to an organization’s Okta, Microsoft Entra, or Google SSO dashboard, which acts as a centralized hub listing all SaaS applications the user has permission to access.

    Example Microsoft Entra SSO dashboard
    Example Microsoft Entra SSO dashboard

    These applications include Salesforce, a primary target of ShinyHunters, Microsoft 365, SharePoint, DocuSign, Slack, Atlassian, Dropbox, Google Drive, and many other internal and third-party platforms.

    For threat actors focused on data theft and extortion, the SSO dashboard becomes a springboard to a company’s cloud data, allowing them to access multiple services from a single compromised account.

    Hardening helpdesk and SSO security

    According to a July 24 advisory, ShinyHunters attacks follow a chain that begins with voice phishing (vishing) to manipulate employees or helpdesk personnel into resetting passwords, changing multifactor authentication methods, or enrolling new devices.

    BleepingComputer previously reported that ShinyHunters is using custom phishing kits built for voice-based social engineering (vishing) attacks.

    These phishing kits are designed for live interaction with targeted employees via voice calls, allowing attackers to change content and display authentication dialogs in real time as a call progresses.

    A C2 panel allowing real-time control of authentication flows
    A C2 panel allowing real-time control of authentication flows
    Source: Okta

    Once an account is breached, the attackers use it to access connected SaaS platforms, where they rapidly steal data that can be used for extortion.

    “SSO is the control plane, and ShinyHunters’ leverage is created through data theft at cloud scale,” Health-ISAC warned.

    The advisory does not identify affected healthcare organizations, disclose how many incidents have been observed, or provide a timeframe for the reported increase.

    However, BleepingComputer is aware of recent ShinyHunters attacks at healthcare and medtech companies, including Medtronic, DentaQuest, iRhythm, and OneMedical.

    Health-ISAC said that in recent incident reporting, ShinyHunters claimed it successfully vished multiple employees, compromised a Microsoft Entra SSO account, and stole data from Microsoft 365, SharePoint, and other enterprise platforms.

    However, the organization cautioned that not every data theft claim has been verified, and defenders should instead focus on the attack pattern of using compromised SSO identities to access and exfiltrate data from connected cloud services.

    Health-ISAC says the most important defensive step is breaking the attack chain between the initial vishing call and the takeover of an SSO account.

    Organizations are advised to require out-of-band identity verification for password resets, MFA resets, and device re-enrollment requests.

    This can include calling users back using a previously verified phone number and requiring manager approval for privileged accounts.

    The advisory also recommends helpdesk personnel follow a “no same-call” policy that prevents resets during the same inbound call. Instead, reset requests should require a support ticket and a verified callback before any changes are made.

    Additional verification should be required when changes are requested for executives, IT administrators, security personnel, finance employees, and other high-risk users.

    Healthcare organizations should also deploy phishing-resistant MFA, such as FIDO2 or WebAuthn security keys, for administrators, helpdesk personnel, executives, and other high-risk groups.

    SMS and voice-based authentication should be disabled or tightly restricted. At the same time, registering new MFA factors should require additional controls, such as a managed device or a conditional access policy.

    Health-ISAC also recommends treating SSO systems as “Tier 0,” which represent the most critical assets in an organization.

    This includes requiring MFA and compliant devices when accessing sensitive cloud services, blocking legacy authentication, detecting sessions with improbable geographic changes, and limiting administrative portals to managed devices.

    Detecting cloud data theft

    Health-ISAC recommends centralizing identity and SaaS audit logs and monitoring for signs of account takeover and large-scale data access, including new MFA registrations, newly enrolled devices, suspicious OAuth grants, unusual API activity, and bulk file downloads.

    Organizations should also restrict API tokens and third-party integrations, require approval for access to sensitive data, and ensure incident response teams can quickly revoke active sessions, reset credentials, and turn off malicious OAuth applications.

    Over the next 30 to 60 days, healthcare organizations are urged to prioritize phishing-resistant MFA for high-risk users, strengthen helpdesk reset procedures, enforce conditional access policies, and test their ability to contain compromised cloud accounts.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    attacks data healthcare HealthISAC rising ShinyHunters theft warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security

    Cisco warns of FMC static credential flaw exploited in zero-day attacks

    Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

    Senate Leaders Push U.S. DOT Over Bus Safety Data — ProPublica

    When AppSec Scanners Become a Supply Chain Attack Vector

    Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Sanctions Bill Would Give Trump Sweeping New Tariff Powers

    July 30, 2026

    Record Numbers of FOIA Public Document Requests Are in Limbo or Unfulfilled

    July 30, 2026

    It Looks Like Nothing Can Dent MAGA’s Support for ICE

    July 30, 2026

    US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security

    July 30, 2026
    Latest Posts

    Who’s in Andy Burnham’s new Labour cabinet?

    July 22, 2026

    Streeting apologises after early prisoner release comments heard on mic

    July 22, 2026

    Mehr Risikokapital, mehr Rüstung – Reiches Start-up-Plan – POLITICO

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Sanctions Bill Would Give Trump Sweeping New Tariff Powers

    July 30, 2026

    Record Numbers of FOIA Public Document Requests Are in Limbo or Unfulfilled

    July 30, 2026

    It Looks Like Nothing Can Dent MAGA’s Support for ICE

    July 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.