logo

Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms

ID: 332c7529-1ebe-5205-93d0-13ecbb79707f

STIX ID: report--332c7529-1ebe-5205-93d0-13ecbb79707f

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-01-31

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Google Mandiant observed an expansion of ShinyHunters-linked extortion activity where multiple clusters (UNC6661, UNC6671, UNC6240) use voice phishing and faux credential-harvesting sites to steal SSO credentials and MFA codes, register attacker MFA devices, and access/exfiltrate sensitive data from SaaS platforms (Okta, SharePoint, OneDrive, Salesforce) for extortion; Google provided hardening and detection recommendations including phishing-resistant MFA, stricter help-desk verification, and enhanced logging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.