logo

Okta Vishing Campaign Allegedly Linked to ShinyHunters: What You Need to Know

ID: 182bf3df-944e-56f8-9eee-57bf6a8d062b

STIX ID: report--182bf3df-944e-56f8-9eee-57bf6a8d062b

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2026-01-23

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Okta disclosed a voice-phishing (vishing) campaign using custom, real-time phishing kits that coordinate with callers to relay credentials and dynamically present MFA prompts, enabling attackers to bypass common MFA methods; the criminal group ShinyHunters claimed responsibility and published alleged data leaks (claims include tens of millions of records for Betterment, Crunchbase, and SoundCloud). Okta recommends phishing-resistant authentication (passkeys/FastPass), network restrictions, blocking anonymization services, and employee awareness to mitigate these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.