ShinyHunters Group Targets Over 100 Enterprises, Including Canva, Atlassian, and Epic Games
ID: ab0fce54-ce41-5f9b-9bd4-1b5f1d7c5be8
STIX ID: report--ab0fce54-ce41-5f9b-9bd4-1b5f1d7c5be8
Feed Name: GBHackers
A sophisticated, human-operated campaign attributed to an SLSH “supergroup” (Scattered Spider + LAPSUS$ + ShinyHunters) targets enterprise SSO providers—especially Okta—using vishing combined with live, interactive phishing panels to capture credentials and MFA tokens in real time; operators then pivot to internal collaboration tools for privilege escalation, rapidly exfiltrate data for extortion, and may deploy encryption/ransom. Silent Push reports active targeting of over 100 high-value organizations and recommends immediate awareness, SSO/Okta forensic auditing (look for new-device enrollments followed by unfamiliar IP logins), DNS-level pre-attack blocking, and other mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
