Health-ISAC has warned healthcare and medical technology organisations about a rise in ShinyHunters healthcare attacks. The extortion group is using voice phishing, or vishing, to take over employee accounts and access cloud platforms containing sensitive business data.
The warning highlights how one compromised single sign-on account can give attackers access to several connected services. These can include Microsoft 365, SharePoint, Salesforce, Google Drive and other widely used enterprise platforms.
ShinyHunters focuses on identities and cloud services
ShinyHunters is an extortion group that has built a reputation through supply chain attacks and identity-based intrusions. Its campaigns often focus on cloud SaaS platforms, storage services and third-party integrations.
Over the past two years, the group has also targeted integration partners to obtain OAuth tokens. Those tokens can connect business applications and cloud services, creating another path into company data.
However, the latest warning centres on social engineering. Attackers target employees and helpdesk workers through phishing calls and fake support requests.
A stolen SSO account can open many doors
Once ShinyHunters gains access to an employee account, it may be able to enter the organisation’s SSO dashboard. Services such as Okta, Microsoft Entra and Google SSO often act as a central hub for approved applications.
From there, attackers may reach platforms including Microsoft 365, SharePoint, Salesforce, DocuSign, Slack, Atlassian, Dropbox and Google Drive.
This makes SSO accounts a valuable target. One stolen identity can give criminals a route to large volumes of data across several cloud services.
Health-ISAC said attackers can use this access to collect data quickly before demanding payment from the victim organisation.
Vishing campaigns pressure employees and helpdesks
The group’s attacks often begin with a phone call. Attackers may pose as an employee, an IT worker or another trusted contact. They then attempt to persuade staff to reset a password, alter MFA settings or enrol a new device.
Health-ISAC said ShinyHunters has reportedly used custom phishing kits built for live vishing operations. These tools can change authentication pages and prompts in real time during a call.
That approach makes the scam harder to spot. The attacker can adapt the conversation as the target responds, increasing the chance that a helpdesk worker or employee approves an unsafe change.
The advisory did not name affected organisations or specify the number of incidents behind the warning. Still, recent reporting has connected ShinyHunters activity to healthcare and medtech companies, including Medtronic, DentaQuest, iRhythm and One Medical.
Helpdesk procedures are a key line of defence
Health-ISAC said the priority is to break the chain between the initial phone call and the takeover of an SSO account.
Organisations should require out-of-band identity verification before resetting passwords, changing MFA methods or registering devices. For example, support teams can call a user back on a previously verified number rather than relying on the details provided during an inbound call.
A no same-call policy can also reduce risk. Under this approach, helpdesk staff do not make security changes while the caller remains on the line. Instead, they create a support ticket and complete a separate verification process before taking action.
Additional checks should apply to executives, IT administrators, security staff, finance teams and other high-risk users.
Phishing-resistant MFA should be prioritised
Health-ISAC recommends phishing-resistant MFA for administrators, helpdesk personnel, executives and other sensitive roles. FIDO2 and WebAuthn security keys can offer stronger protection than SMS or voice-based authentication.
Healthcare organisations should disable or tightly limit SMS and voice authentication. They should also apply stricter controls when users register a new MFA method or device.
Conditional access policies can help by requiring managed devices and stronger verification before permitting access to sensitive cloud services.
Health-ISAC also urged organisations to treat SSO environments as Tier 0 assets. In practice, this means applying the strongest security controls to identity systems that can unlock access across the wider business.
Monitor cloud platforms for signs of data theft
Security teams should centralise identity and SaaS audit logs to improve detection. They should investigate new MFA registrations, unfamiliar devices, suspicious OAuth permissions, unusual API activity and large file downloads.
Organisations should also review API tokens and third-party integrations. Sensitive data access should be restricted, monitored and approved where necessary.
Incident response teams need to be ready to revoke active sessions, reset credentials and disable malicious OAuth applications quickly.
Over the next 30 to 60 days, Health-ISAC recommends healthcare organisations focus on phishing-resistant MFA, tougher helpdesk procedures, conditional access controls and tested cloud-account response plans.


0 responses to “ShinyHunters Healthcare Attacks Raise New Cloud Data Theft Concerns”