logo

“IT Support” Imposters: ShinyHunters Vishing Rings Bypass MFA to Steal Data

ID: 68ccd018-e390-5163-9655-b392043904d3

STIX ID: report--68ccd018-e390-5163-9655-b392043904d3

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-23

Author: Ddos

...
...

Mandiant and GTIG report a surge in sophisticated voice-phishing (vishing) campaigns attributed to clusters UNC6661, UNC6671, and UNC6240 that use live phone calls and victim-branded credential harvesting sites to capture SSO credentials and MFA codes. After gaining access, operators directly target cloud SaaS environments (including Okta, SharePoint, and OneDrive) to exfiltrate sensitive data and carry out extortion, with UNC6671 also observed using Tucows-registered domains, PowerShell-based data retrieval, and harassment of personnel. Recommended defenses emphasize user training to verify callers and deploying hardware-based MFA keys to resist phishing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.