Health-ISAC warns ShinyHunters is increasingly targeting healthcare with vishing-led SSO account takeovers and cloud data theft

Health-ISAC says ShinyHunters is increasingly breaching healthcare and medical-technology organizations by tricking staff or help desks into resetting passwords or multifactor authentication, then stealing data from cloud services. The July 24 advisory says the group uses voice phishing (vishing) to take over single sign-on accounts in Okta, Microsoft Entra, or Google environments, then pivots into connected platforms such as Microsoft 365, SharePoint, Salesforce, DocuSign, Slack, Atlassian, Dropbox, and Google Drive for rapid data theft and extortion.
Why it matters: This matters because one successful fake IT call can open many connected business systems at once, putting patient, employee, and corporate data at risk. Healthcare organizations should urgently tighten help-desk identity checks, require out-of-band verification for password and MFA resets, and review SSO-linked cloud access.

Sources

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
Lawrence Abrams 2026.07.29 100% relevant
This article establishes a new sector-wide story because it is an industry warning about a rising pattern of ShinyHunters attacks on healthcare, not a follow-up on any one previously tracked victim incident.
← Back to all stories