Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms
ID: 332c7529-1ebe-5205-93d0-13ecbb79707f
STIX ID: report--332c7529-1ebe-5205-93d0-13ecbb79707f
Feed Name: The Hacker News
Google Mandiant observed an expansion of ShinyHunters-linked extortion activity where multiple clusters (UNC6661, UNC6671, UNC6240) use voice phishing and faux credential-harvesting sites to steal SSO credentials and MFA codes, register attacker MFA devices, and access/exfiltrate sensitive data from SaaS platforms (Okta, SharePoint, OneDrive, Salesforce) for extortion; Google provided hardening and detection recommendations including phishing-resistant MFA, stricter help-desk verification, and enhanced logging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
