ShinyHunters vishing campaign targeting SSO accounts
Campaign
Summary
Hide ▲
Show ▼
The ShinyHunters group ran a voice phishing campaign against single sign-on (SSO) accounts at Okta, Microsoft, and Google, widening risk across more than 100 high-profile organizations. The operation mattered because it used account-access abuse rather than a one-off intrusion, creating repeatable exposure across many targets. The campaign was active in late January 2026 and tied to credential theft and follow-on data access.
Related Happenings
Kali365 Microsoft 365 device-code phishing campaign
Campaign
First: 25.05.2026 15:45
Last: 25.05.2026 15:45
Sources 1
About this happening:
A **Kali365** phishing campaign is targeting **Microsoft 365** environments worldwide with **device-code login lures**, putting accounts at risk of **token theft** and **MFA bypas...
Kali365 Microsoft 365 device-code phishing campaign
CampaignAbout this happening: A **Kali365** phishing campaign is targeting **Microsoft 365** environments worldwide with **device-code login lures**, putting accounts at risk of **token theft** and **MFA bypas...
Infostealer malware operation targeting online store users
Malware Activity
First: 21.05.2026 00:36
Last: 21.05.2026 00:36
Sources 1
About this happening:
A **malware operation** using **infostealer** tools infected users’ devices between **2024 and 2025**, stealing browser sessions and account credentials that enabled account theft...
Infostealer malware operation targeting online store users
Malware ActivityAbout this happening: A **malware operation** using **infostealer** tools infected users’ devices between **2024 and 2025**, stealing browser sessions and account credentials that enabled account theft...
Storm-2949 Microsoft 365 and Azure data-theft campaign
Campaign
First: 19.05.2026 22:35
Last: 19.05.2026 22:35
Sources 1
About this happening:
The **Storm-2949** campaign is targeting **Microsoft 365 and Azure production environments** to steal sensitive data, increasing the risk of privileged-account takeover and cloud...
Storm-2949 Microsoft 365 and Azure data-theft campaign
CampaignAbout this happening: The **Storm-2949** campaign is targeting **Microsoft 365 and Azure production environments** to steal sensitive data, increasing the risk of privileged-account takeover and cloud...
EvilTokens Microsoft 365 consent phishing campaign
Campaign
First: 19.05.2026 14:30
Last: 19.05.2026 14:30
Sources 1
About this happening:
The **EvilTokens** campaign rapidly compromised **more than 340 Microsoft 365 organizations** across **five countries**, showing how **OAuth grant abuse** can bypass **MFA** and c...
EvilTokens Microsoft 365 consent phishing campaign
CampaignAbout this happening: The **EvilTokens** campaign rapidly compromised **more than 340 Microsoft 365 organizations** across **five countries**, showing how **OAuth grant abuse** can bypass **MFA** and c...
Open-source admin tool zero-day 2FA bypass exploitation wave
Exploitation Wave
First: 11.05.2026 18:45
Last: 11.05.2026 18:45
Sources 1
About this happening:
Google identified a **mass vulnerability exploitation operation** using a **zero-day 2FA bypass** against a **popular open-source, web-based system administration tool**, creating...
Open-source admin tool zero-day 2FA bypass exploitation wave
Exploitation WaveAbout this happening: Google identified a **mass vulnerability exploitation operation** using a **zero-day 2FA bypass** against a **popular open-source, web-based system administration tool**, creating...
Timeline
-
26.05.2026 22:46 1 articles · 23h ago
ShinyHunters claims Charter Communications data theft via Salesforce access
Victim Impact UpdateShinyHunters claims it breached Charter Communications on April 1 by vishing an employee's Microsoft Entra account, then used that access to export millions of consumer and business customer records from the company's Salesforce instance; Charter says no sensitive personal information or CPNI was exfiltrated.
Show sources
- Charter confirms data breach after ShinyHunters extortion threat — www.bleepingcomputer.com — 26.05.2026 22:46
-
23.02.2026 20:04 2 articles · 3mo ago
ShinyHunters vishing campaign adds device code abuse
Campaign Scope UpdateShinyHunters-linked operators expanded a voice-phishing campaign that targeted single sign-on (SSO) accounts at Microsoft, Okta, and Google across more than 100 high-profile organizations, and they also shifted to device code vishing that abuses the OAuth 2.0 device authorization grant flow to obtain Microsoft Entra authentication tokens.
Show sources
- Ad tech firm Optimizely confirms data breach after vishing attack — www.bleepingcomputer.com — 23.02.2026 20:04
- ADT confirms data breach after ShinyHunters leak threat — www.bleepingcomputer.com — 25.04.2026 01:53
-
02.02.2026 15:46 3 articles · 3mo ago
ShinyHunters vishing campaign targeting SSO accounts
Initial DisclosureIn **late January 2026**, **ShinyHunters** began a **vishing** push aimed at **SSO accounts** tied to major identity platforms. The initial phase used voice phishing and account-access abuse to reach a broad set of organizations.
Show sources
- Panera Bread breach impacts 5.1 million accounts, not 14 million customers — www.bleepingcomputer.com — 02.02.2026 15:46
- Panera Bread breach impacts 5.1 million accounts, not 14 million customers — www.bleepingcomputer.com — 02.02.2026 15:46
- Data breach at fintech firm Figure affects nearly 1 million accounts — www.bleepingcomputer.com — 18.02.2026 16:01