logo

ShinyHunters Expands Scope of SaaS Extortion Attacks

ID: 7a9238f2-603f-530e-9877-23eb8f09ebe1

STIX ID: report--7a9238f2-603f-530e-9877-23eb8f09ebe1

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-02-02

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Mandiant and Google report that the ShinyHunters cybercrime collective has expanded SaaS-focused extortion operations (clusters UNC6661, UNC6671, UNC6240), using vishing and company‑branded credential‑harvesting sites to capture SSO credentials and MFA codes, register attacker devices, move laterally within cloud environments (Microsoft 365, SharePoint, Slack, Salesforce), exfiltrate sensitive data for leverage in ransom demands, and negotiate via branded extortion messages and messaging platforms; defenders are advised to harden SaaS configurations, monitor phishing domain patterns, and adopt phishing‑resistant authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.