Skip to content
Breaking
Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech
SECURITY

Analysis: ShinyHunters claim to be behind SSO-account data theft attacks

ShinyHunters' Voice Phishing Attacks: A Growing Threat

ShinyHunters' Voice Phishing Attacks: A Growing Threat

In the digital age, where businesses rely heavily on cloud services and single sign-on (SSO) systems, a new form of cyber threat has emerged: voice phishing attacks. The ShinyHunters extortion gang is allegedly behind a wave of these attacks, targeting SSO accounts at major tech companies like Okta, Microsoft, and Google.

The Attacks and Their Impact

Threat actors impersonate IT support, tricking employees into entering their credentials and multi-factor authentication (MFA) codes on phishing sites that mimic company login portals. Once compromised, the attackers gain access to the victim's SSO account, which can provide access to other connected enterprise applications and services. This makes a compromised account a gateway into corporate systems and data.

Connected Applications and Services

Commonly connected applications and services through SSO include Salesforce, Microsoft 365, Google Workspace, Dropbox, Adobe, SAP, Slack, Zendesk, Atlassian, and many others. These SSO dashboards typically list all connected services, making a compromised account a potential entry point into a corporation's digital infrastructure.

Social Engineering and Phishing Kits

The attacks involve social engineering, where threat actors convince employees to log into phishing pages and complete MFA challenges in real time. The phishing kits used in these voice-based attacks include a web-based control panel, allowing attackers to dynamically change what a victim sees on a phishing site while speaking to them on the phone.

ShinyHunters' Claims and Responses

ShinyHunters initially declined to comment on the attacks but later confirmed to BleepingComputer that it is responsible for some of the social engineering attacks. The group is targeting not only Okta but also Microsoft Entra and Google SSO platforms.

Relevance to North East India and Broader Indian Context

The increasing prevalence of voice phishing attacks is a concern for businesses worldwide, including those in North East India and the broader Indian context. As more companies adopt cloud services and SSO systems, they become potential targets for such attacks. It is crucial for businesses to implement robust cybersecurity measures and employee training programs to protect against such threats.

Future Implications

The ShinyHunters case underscores the need for continued vigilance and investment in cybersecurity. As attackers evolve their tactics, businesses must stay ahead by adopting advanced security measures and keeping employees informed about potential threats. The ongoing investigation into the ShinyHunters' activities will provide valuable insights into the methods used by such groups and how they can be countered.