logo

Mandiant details how ShinyHunters abuse SSO to steal cloud data

ID: a2c94875-724e-543e-96f1-3fcd0f6159f5

STIX ID: report--a2c94875-724e-543e-96f1-3fcd0f6159f5

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-01-31

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Mandiant and Google Threat Intelligence report that ShinyHunters and affiliated clusters (UNC6661, UNC6671, UNC6240) conduct targeted vishing attacks combined with advanced phishing kits to steal SSO credentials and MFA codes, enroll attacker MFA devices, pivot into Okta/Microsoft Entra/Google SSO dashboards and mass-exfiltrate SaaS data (Salesforce, M365, SharePoint, DocuSign, etc.) for extortion; the report includes observed IOCs, phishing domain naming patterns, examples of logs, and recommended hardening and detection controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.