Security · 1h ago
ShinyHunters Exploit Vishing, Help Desk to Steal SaaS Data via SSO
Health-ISAC warns of rising ShinyHunters attacks using vishing and help desk manipulation to compromise SSO and steal data from healthcare orgs. Attackers impersonate IT support to reset passwords and MFA, then access M365, Salesforce, and other SaaS apps. The group targets bulk data theft via legitimate sessions, often without malware.
Meridian48 take
The attack highlights how weak identity verification at help desks and user susceptibility to vishing can bypass even strong SSO protections.
Read the full reporting
ShinyHunters: Breaking Help Desks via Vishing and Bulk Stealing SaaS via SSO →
DEV Community
shinyhunterssso-attacks