ShinyHunters uses voice phishing to get past MFA on SSO accounts
The extortion group ShinyHunters has been linked to a wave of voice phishing attacks against single sign-on accounts on major identity platforms, including Okta, Microsoft Entra and Google. The attackers pose as IT support over the phone and get employees to enter credentials and multi-factor details on fake login pages, bypassing MFA and reaching corporate SaaS dashboards. Once inside, the compromised SSO accounts open a wide range of services such as Salesforce, Microsoft 365, Google Workspace and Slack. Stolen data is used for extortion, and organisations including SoundCloud, Betterment and Crunchbase have reportedly been named on the group's leak site.
What this means for your organisation
Single sign-on exists precisely because it provides one door into everything. That is also the whole problem when the door is opened by an employee who believes she is helping the IT department. The attack requires no vulnerability in any system, only a convincing phone call, and it hits organisations with mature technical security just as hard as anyone else. The consequence is rarely just lost access, but a demand for payment over data that is already gone.
Berigo recommends
- Move to phishing-resistant authentication, such as passkeys or FIDO2 keys, on your SSO platform.
- Establish a fixed, well-known channel for verifying IT support, and make it legitimate for staff to end a call.
- Apply conditional access rules that restrict sign-in from unknown devices and locations.
- Exercise the compromised-SSO-account scenario, including revoking active sessions and reviewing connected applications.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch