Skip to main content
Emerging ThreatsData Breaches

ShinyHunters Targets Healthcare with Rising Data Theft Attacks

Hospital corridor with laptop and medical records on counter, hinting at potential data breach.

"SSO is the control plane, and ShinyHunters' leverage is created through data theft at cloud scale," Health-ISAC warned.

ShinyHunters’ supply-chain and identity playbook

Health-ISAC says the extortion gang known as ShinyHunters has increased successful data theft attacks targeting healthcare and medical-technology organizations. Over the past two years, the group has become notable for supply-chain breaches of third-party integration partners that yield OAuth tokens used to integrate with SaaS platforms such as Salesforce and Snowflake. The group also conducts identity attacks that focus on people — employees and helpdesk staff — using social engineering including vishing and phishing to seize corporate single-sign-on (SSO) accounts.

BleepingComputer reported that ShinyHunters has been observed targeting SSO dashboards — including Okta, Microsoft Entra, and Google SSO — because those dashboards list every SaaS application an account can access. Health-ISAC lists Salesforce as a primary target and names other frequently targeted platforms: Microsoft 365, SharePoint, DocuSign, Slack, Atlassian, Dropbox, Google Drive and many other internal and third‑party services.

How vishing turns a single account into cloud-wide access

According to a July 24 advisory from Health-ISAC, the attack chain typically begins with voice phishing (vishing). Attackers call employees or helpdesk personnel to manipulate them into performing resets — changing passwords, resetting multifactor authentication (MFA), or enrolling new devices. BleepingComputer says attackers are even employing custom phishing kits built for live, voice-based social-engineering interactions; the kits allow attackers to change content and display authentication dialogs in real time during a call.

Once an account is compromised, the SSO dashboard becomes a springboard: from a single breached identity, attackers can access connected SaaS platforms and rapidly exfiltrate data for extortion. Health-ISAC notes the group claimed recent successes, saying it had vished multiple employees, compromised a Microsoft Entra SSO account, and stolen data from Microsoft 365, SharePoint and other enterprise platforms — while cautioning that not every theft claim has been independently verified.

Hardening helpdesk and SSO security: specific controls Health-ISAC recommends

To break the chain between the initial vishing call and SSO takeover, Health-ISAC lists concrete controls for healthcare organizations. Key recommendations include:

  • Require out-of-band identity verification for password resets, MFA resets and device re-enrollments — for example, calling users back on a previously verified phone number and requiring manager approval for privileged accounts.
  • Enforce a "no same-call" policy for helpdesk staff: do not perform resets during the same inbound call; instead require a support ticket and a verified callback before making changes.
  • Require additional verification for executives, IT administrators, security personnel, finance employees and other high‑risk users.
  • Deploy phishing-resistant MFA such as FIDO2 or WebAuthn security keys for administrators, helpdesk personnel, executives and other high-risk groups, and disable or tightly restrict SMS and voice-based authentication.
  • Require extra controls before registering new MFA factors — for example, only allowing registration from a managed device or under a conditional access policy.
  • Treat SSO systems as "Tier 0" assets: require MFA and compliant devices to access sensitive cloud services, block legacy authentication, detect sessions with improbable geographic changes, and limit administrative portals to managed devices.

Detecting and containing cloud data theft

Health-ISAC urges centralization of identity and SaaS audit logs and active monitoring for signs of account takeover and large-scale data access. Recommended detections include watching for new MFA registrations, newly enrolled devices, suspicious OAuth grants, unusual API activity, and bulk file downloads. Organizations should restrict API tokens and third-party integrations, require approvals for access to sensitive data, and ensure incident-response teams can rapidly revoke active sessions, reset credentials, and disable malicious OAuth applications.

The advisory sets an operational timeline: over the next 30 to 60 days, healthcare organizations are urged to prioritize phishing-resistant MFA for high‑risk users, strengthen helpdesk reset procedures, enforce conditional access policies, and test their ability to contain compromised cloud accounts.

What this means for healthcare technologists, procurement leaders, and helpdesk personnel

  • Healthcare technologists and security teams: centralize identity and SaaS logs, monitor for the specific telemetry Health-ISAC lists (new MFA enrollments, suspicious OAuth grants, bulk downloads), and treat SSO as a Tier 0 control point requiring managed devices and conditional access.
  • Procurement and vendor managers: closely restrict API tokens and third‑party integrations, require approvals before granting access to sensitive data, and reassess integration partners that could expose OAuth tokens used to integrate with SaaS providers such as Salesforce and Snowflake.
  • Helpdesk personnel and administrators: adopt a "no same-call" policy, require out-of-band callbacks and manager approval for privileged resets, and ensure additional verification for high‑risk user accounts.

Health-ISAC’s advisory does not identify which healthcare organizations were affected, the number of incidents observed, or a broader timeframe for the reported increase — even as BleepingComputer says it is aware of recent ShinyHunters attacks at Medtronic, DentaQuest, iRhythm and OneMedical. The advisory makes clear that the core danger is not a single exploited app but the leverage an attacker gains when a compromised identity unlocks multiple cloud services. For healthcare organizations, the next 30–60 days will be a test of whether tightened helpdesk controls and phishing‑resistant MFA can blunt an attack method that weaponizes the human voice against the cloud.

https://www.bleepingcomputer.com/news/security/health-isac-warns-of-rising-shinyhunters-data-theft-attacks-on-healthcare/