← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Health-ISAC warns healthcare sector of increased ShinyHunters data theft attacks

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Health-ISAC warns of increased ShinyHunters attacks.
  • ShinyHunters uses supply chain and identity attacks.
  • Attacks target cloud SaaS and storage platforms.
  • Social engineering, including vishing, is a primary method.

Rising Threat to Healthcare

Health-ISAC, a cybersecurity information-sharing organization for the health sector, has alerted healthcare and medical technology organizations to an observed increase in successful attacks by the ShinyHunters extortion gang. This group specializes in data theft and extortion, posing a significant risk to sensitive health information.

ShinyHunters' Attack Methods

ShinyHunters conducts supply chain and identity attacks to breach cloud SaaS and storage platforms. Over the past two years, the group has become known for supply chain attacks on third-party integration partners, gaining access to OAuth tokens for SaaS providers like Salesforce and Snowflake. They also employ identity attacks, targeting employees through social engineering techniques such as vishing and phishing to compromise corporate single-sign-on (SSO) accounts.

Exploiting Single Sign-On

Once an employee's SSO account is compromised, ShinyHunters can access centralized dashboards like Okta, Microsoft Entra, or Google SSO. These dashboards list all SaaS applications the user can access, including Salesforce, Microsoft 365, SharePoint, DocuSign, Slack, Atlassian, Dropbox, and Google Drive. This access allows the attackers to use the SSO dashboard as a springboard to a company's cloud data, enabling rapid data theft for extortion purposes.

Vishing as an Initial Vector

According to a July 24 advisory, ShinyHunters attacks often begin with voice phishing (vishing). This technique manipulates employees or helpdesk personnel into resetting passwords, changing multifactor authentication methods, or enrolling new devices. Custom phishing kits are used for live interaction during these voice calls, allowing attackers to dynamically change content and display authentication dialogs.

Impact and Data Exfiltration

After breaching an account, the attackers quickly access connected SaaS platforms to steal data. Health-ISAC emphasized that "SSO is the control plane, and ShinyHunters' leverage is created through data theft at cloud scale." The advisory did not specify the number of incidents, affected organizations, or the timeframe for the reported increase in attacks.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Health-ISAC has issued a warning to healthcare and medical technology organizations about a rise in successful data theft attacks by the ShinyHunters extortion gang. ShinyHunters primarily uses supply chain and identity attacks, often involving social engineering, to breach cloud SaaS and storage platforms, leading to data exfiltration and extortion. This increase in attacks highlights the ongoing vulnerability of healthcare data to sophisticated cybercriminal groups.