logo

ShinyHunters Leads Surge in Vishing Attacks to Steal SaaS Data

ID: a24788f9-842c-5ef6-82f4-bacac5e3133b

STIX ID: report--a24788f9-842c-5ef6-82f4-bacac5e3133b

Feed Name: Security Boulevard

Threat Score
80/100

Date Published: 2026-02-02

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

**Executive Summary:** Mandiant and other industry researchers are tracking a surge of extortion-focused campaigns tied to ShinyHunters and affiliated clusters that employ sophisticated, human-led vishing and targeted credential-harvesting sites to bypass SSO/MFA, access SaaS environments, exfiltrate sensitive data, and pressure victims with extortion and harassment; the activity has produced large data exposures (millions of records) and leverages custom vishing kits and overlapping threat clusters (UNC6240/UNC6661/UNC6671).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.