ShinyHunters Expands Scope of SaaS Extortion Attacks
ID: 7a9238f2-603f-530e-9877-23eb8f09ebe1
STIX ID: report--7a9238f2-603f-530e-9877-23eb8f09ebe1
Feed Name: Dark Reading
Date Published: 2026-02-02
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Mandiant and Google report that the ShinyHunters cybercrime collective has expanded SaaS-focused extortion operations (clusters UNC6661, UNC6671, UNC6240), using vishing and company‑branded credential‑harvesting sites to capture SSO credentials and MFA codes, register attacker devices, move laterally within cloud environments (Microsoft 365, SharePoint, Slack, Salesforce), exfiltrate sensitive data for leverage in ransom demands, and negotiate via branded extortion messages and messaging platforms; defenders are advised to harden SaaS configurations, monitor phishing domain patterns, and adopt phishing‑resistant authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
