← Back to Feed

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

July 29, 2026 · BleepingComputer · Severity: MEDIUM

Health-ISAC is warning healthcare and medical technology organizations about a significant increase in successful attacks by the ShinyHunters extortion gang. The threat actors specialize in supply chain and identity attacks, using voice phishing (vishing) to manipulate employees and helpdesk personnel into resetting passwords, changing MFA methods, or enrolling new devices. Once they compromise a corporate single-sign-on (SSO) account — typically via Okta, Microsoft Entra, or Google SSO — they gain a centralized springboard to access multiple SaaS platforms including Salesforce, Microsoft 365, SharePoint, DocuSign, Slack, and Dropbox. Recent victims in healthcare include Medtronic, DentaQuest, iRhythm, and OneMedical. Health-ISAC advises treating SSO systems as Tier 0 critical assets, implementing out-of-band identity verification for password resets, deploying phishing-resistant MFA (FIDO2/WebAuthn), and enforcing 'no same-call' policies for helpdesk resets.

Key Takeaways

  • ShinyHunters uses vishing to bypass MFA — Attackers socially engineer employees and helpdesk staff via voice calls to reset passwords, change MFA factors, or enroll new devices.
  • SSO is the 'control plane' for data theft — Once a single SSO account is compromised, attackers access every connected SaaS app (Salesforce, M365, SharePoint, Slack, Dropbox, etc.) to steal data at cloud scale.
  • Out-of-band verification is critical — Organizations should require callback to a verified phone number and manager approval for password/MFA resets, plus enforce a 'no same-call' policy.
☕ Buy a Coffee