logo

ShinyHunters Group Targets Over 100 Enterprises, Including Canva, Atlassian, and Epic Games

ID: ab0fce54-ce41-5f9b-9bd4-1b5f1d7c5be8

STIX ID: report--ab0fce54-ce41-5f9b-9bd4-1b5f1d7c5be8

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-01-27

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A sophisticated, human-operated campaign attributed to an SLSH “supergroup” (Scattered Spider + LAPSUS$ + ShinyHunters) targets enterprise SSO providers—especially Okta—using vishing combined with live, interactive phishing panels to capture credentials and MFA tokens in real time; operators then pivot to internal collaboration tools for privilege escalation, rapidly exfiltrate data for extortion, and may deploy encryption/ransom. Silent Push reports active targeting of over 100 high-value organizations and recommends immediate awareness, SSO/Okta forensic auditing (look for new-device enrollments followed by unfamiliar IP logins), DNS-level pre-attack blocking, and other mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.