Healthcare Organizations Warned of Rising ShinyHunters Data Theft Attacks
A growing number of healthcare and medical technology organizations are being targeted by an extortion gang known as ShinyHunters. This group has been notorious for conducting supply chain attacks, identity theft, and data breaches on cloud-based platforms, leaving sensitive information vulnerable to exploitation.
ShinyHunters uses a sophisticated approach to gain access to cloud services, starting with voice phishing (vishing) calls that manipulate employees or helpdesk personnel into resetting passwords or changing multifactor authentication methods. Once an account is compromised, the attackers use it as a springboard to access connected SaaS platforms, where they rapidly steal data for extortion.
The threat actors are particularly interested in cloud services such as Salesforce, Microsoft 365, and Google Drive, which often rely on single-sign-on (SSO) dashboards to manage user permissions. ShinyHunters exploits these vulnerabilities by compromising corporate SSO accounts, allowing them to access multiple services from a single compromised account.
The Health-ISAC, a cybersecurity information-sharing organization for the health sector, has issued an advisory warning healthcare organizations of this rising threat. According to their analysis, ShinyHunters’ attacks often follow a predictable pattern, starting with vishing calls that manipulate employees into compromising SSO accounts. Once inside, the attackers use these compromised identities to access and exfiltrate data from connected cloud services.
Health-ISAC recommends several defensive measures to break this attack chain. Organizations should require out-of-band identity verification for password resets, MFA resets, and device re-enrollment requests. This can include calling users back using a previously verified phone number or requiring manager approval for privileged accounts. Additionally, helpdesk personnel should follow a “no same-call” policy that prevents resets during the same inbound call.
Furthermore, healthcare organizations are advised to deploy phishing-resistant MFA, such as FIDO2 or WebAuthn security keys, for administrators, helpdesk personnel, executives, and other high-risk groups. SMS and voice-based authentication should be disabled or tightly restricted, and registering new MFA factors should require additional controls, such as a managed device or conditional access.
The advisory does not disclose specific affected healthcare organizations, but BleepingComputer has reported recent ShinyHunters attacks on companies like Medtronic, DentaQuest, iRhythm, and OneMedical. While the exact number of incidents is unknown, Health-ISAC warns that these attacks pose a significant threat to sensitive healthcare data.
To protect against this growing threat, healthcare organizations should take immediate action to harden their helpdesk and SSO security. By breaking the attack chain between vishing calls and compromised SSO identities, organizations can prevent ShinyHunters from exploiting vulnerabilities in cloud services.
Source: Bleeping Computer — 2026-07-29