Healthcare Organizations Under Siege: Rising ShinyHunters Data Theft Attacks Exposed
Cybersecurity threat actors are once again targeting healthcare and medical technology organizations with brazen data theft attacks. The Health-ISAC, a cybersecurity information-sharing organization for the health sector, has sounded the alarm on an alarming increase in successful attacks by ShinyHunters, a notorious extortion gang that’s been making headlines over the past two years.
ShinyHunters’ modus operandi is to conduct supply chain and identity attacks to breach cloud SaaS and storage platforms. They’ve become infamous for targeting third-party integration partners through sophisticated social engineering tactics, often using voice phishing (vishing) to manipulate employees or helpdesk personnel into resetting passwords or changing multifactor authentication methods. Once they gain access to an account, they use it as a springboard to access multiple services from connected SaaS platforms, stealing data that can be used for extortion.
Health-ISAC warns that ShinyHunters’ attacks have become increasingly brazen, with the group claiming successful vishing attacks on employees and compromising Microsoft Entra SSO accounts. However, not all claims of data theft have been verified, and defenders are advised to focus on the attack pattern rather than individual incidents. The most critical defensive step is breaking the chain between the initial vishing call and the takeover of an SSO account.
To combat these attacks, Health-ISAC advises healthcare organizations to take several key steps. First, they should require out-of-band identity verification for password resets, MFA resets, and device re-enrollment requests. This can include calling users back using a previously verified phone number and requiring manager approval for privileged accounts. Helpdesk personnel should also follow a “no same-call” policy that prevents resets during the same inbound call.
In addition to these measures, Health-ISAC recommends deploying phishing-resistant MFA, such as FIDO2 or WebAuthn security keys, for administrators, helpdesk personnel, executives, and other high-risk groups. SMS and voice-based authentication should be disabled or tightly restricted, and registering new MFA factors should require additional controls.
The ShinyHunters attacks are a stark reminder of the ongoing threat posed by sophisticated cybercriminals to healthcare organizations. As we’ve seen with previous incidents at companies like Medtronic, DentaQuest, iRhythm, and OneMedical, these groups will stop at nothing to exploit vulnerabilities in cloud services and SSO accounts.
Healthcare organizations must take proactive measures to protect themselves from these types of attacks. By hardening their helpdesk and SSO security, they can break the attack chain and prevent ShinyHunters from using compromised identities to access and exfiltrate sensitive data. The time to act is now – our collective cybersecurity defenses depend on it.
Source: Bleeping Computer — 2026-07-29