Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Thieves Stole ‘Nvidia’ Trailers. They Got 20 Tons of Sand

    September 25, 2026

    Appeals Court Lets the Pentagon Designate Anthropic a Supply-Chain Risk

    September 25, 2026

    Young organs may not be a fountain of youth for recipients

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Thieves Stole ‘Nvidia’ Trailers. They Got 20 Tons of Sand
    • Appeals Court Lets the Pentagon Designate Anthropic a Supply-Chain Risk
    • Young organs may not be a fountain of youth for recipients
    • How Would AI Actually Kill All Humans? Here Are the Top 5 Scenarios
    • Social Media Bans for Kids Need Smarter Safety Design
    • The Pentagon wants $30 million to build an AI-powered lie detector
    • Google’s Gemini Can Now Make Calls for You on Pixel Phones
    • EPICS in IEEE Team Builds Portable Educational Platform
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»ShinyHunters claim to be behind SSO-account data theft attacks
    Cybersecurity

    ShinyHunters claim to be behind SSO-account data theft attacks

    kirklandc008@gmail.comBy kirklandc008@gmail.comJanuary 24, 2026No Comments5 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Hacker making phone calls
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The ShinyHunters extortion gang claims it is behind a wave of ongoing voice phishing attacks targeting single sign-on (SSO) accounts at Okta, Microsoft, and Google, enabling threat actors to breach corporate SaaS platforms and steal company data for extortion.

    In these attacks, threat actors impersonate IT support and call employees, tricking them into entering their credentials and multi-factor authentication (MFA) codes on phishing sites that impersonate company login portals.

    Once compromised, the attackers gain access to the victim’s SSO account, which can provide access to other connected enterprise applications and services.

    SSO services from Okta, Microsoft Entra, and Google enable companies to link third-party applications into a single authentication flow, giving employees access to cloud services, internal tools, and business platforms with a single login. 

    These SSO dashboards typically list all connected services, making a compromised account a gateway into corporate systems and data.

    Platforms commonly connected through SSO include Salesforce, Microsoft 365, Google Workspace, Dropbox, Adobe, SAP, Slack, Zendesk, Atlassian, and many others.

    Microsoft Entra single sign-on (SSO) dashboard
    Source: Microsoft

    Vishing attacks used for data theft

    As first reported by BleepingComputer, threat actors have been carrying out these attacks by calling employees and posing as IT staff, using social engineering to convince them to log into phishing pages and complete MFA challenges in real time.

    After gaining access to a victim’s SSO account, the attackers browse the list of connected applications and begin harvesting data from the platforms available to that user.

    BleepingComputer is aware of multiple companies targeted in these attacks that have since received extortion demands signed by ShinyHunters, indicating that the group was behind the intrusions.

    BleepingComputer contacted Okta earlier this week about the breaches, but the company declined to comment on the data theft attacks.

    However, Okta released a report yesterday describing the phishing kits used in these voice-based attacks, which match what BleepingComputer has been told.

    According to Okta, the phishing kits include a web-based control panel that allows attackers to dynamically change what a victim sees on a phishing site while speaking to them on the phone. This allows threat actors to guide victims through each step of the login and MFA authentication process.

    If the attackers enter stolen credentials into the real service and are prompted for MFA, they can display new dialog boxes on the phishing site in real time to instruct a victim to approve a push notification, enter a TOTP code, or perform other authentication steps.

    A phishing kit lets attackers display different dialogs while calling victims
    Source: Okta

    ShinyHunters claim responsibility

    While ShinyHunters declined to comment on the attacks last night, the group confirmed to BleepingComputer this morning that it is responsible for some of the social engineering attacks.

    “We confirm we are behind the attacks,” ShinyHunters told BleepingComputer. “We are unable to share further details at this time, besides the fact that Salesforce remains our primary interest and target, the rest are benefactors.”

    The group also confirmed other aspects of BleepingComputer’s reporting, including details about the phishing infrastructure and domains used in the campaign. However, it disputed that a screenshot of a phishing kit command-and-control server shared by Okta was for its platform, claiming instead that theirs was built in-house.

    ShinyHunters claimed it is targeting not only Okta but also Microsoft Entra and Google SSO platforms.

    Microsoft said it has nothing to share at this time, and Google said it had no evidence its products were being abused in the campaign.

    “At this time, we have no indication that Google itself or its products are affected by this campaign,” a Google spokesperson told BleepingComputer.

    ShinyHunters claims to be using data stolen in previous breaches, such as the widespread Salesforce data theft attacks, to identify and contact employees. This data includes phone numbers, job titles, names, and other details used to make the social-engineering calls more convincing.

    Last night, the group relaunched its Tor data leak site, which currently lists breaches at SoundCloud, Betterment, and Crunchbase.

    SoundCloud previously disclosed a data breach in December 2025, while Betterment confirmed this month that its email platform had been abused to send cryptocurrency scams and that data was stolen.

    Crunchbase, which had not previously disclosed a breach, confirmed today that data was stolen from its corporate network.

    “Crunchbase detected a cybersecurity incident where a threat actor exfiltrated certain documents from our corporate network,” a company spokesperson told BleepingComputer. “No business operations have been disrupted by this incident. We have contained the incident and our systems are secure.”

    “Upon detecting the incident we engaged cybersecurity experts and contacted federal law enforcement. We are reviewing the impacted information to determine if any notifications are required consistent with applicable legal requirements.”

    Whether you’re cleaning up old keys or setting guardrails for AI-generated code, this guide helps your team build securely from the start.

    Get the cheat sheet and take the guesswork out of secrets management.

    Download Now

    Attacks claim data ShinyHunters SSOaccount theft
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    How to Claim Your Cut of Apple’s $250 Million Siri Settlement

    September 22, 2026

    Shortwave Radio Gets a Secure Data Upgrade With HERMES

    September 21, 2026

    It’s Donald Trump Versus MAGA on Data Centers

    September 20, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Thieves Stole ‘Nvidia’ Trailers. They Got 20 Tons of Sand
    • Appeals Court Lets the Pentagon Designate Anthropic a Supply-Chain Risk
    • Young organs may not be a fountain of youth for recipients
    • How Would AI Actually Kill All Humans? Here Are the Top 5 Scenarios
    • Social Media Bans for Kids Need Smarter Safety Design

    Thieves Stole ‘Nvidia’ Trailers. They Got 20 Tons of Sand

    September 25, 2026

    Appeals Court Lets the Pentagon Designate Anthropic a Supply-Chain Risk

    September 25, 2026

    Young organs may not be a fountain of youth for recipients

    September 25, 2026

    How Would AI Actually Kill All Humans? Here Are the Top 5 Scenarios

    September 25, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.