ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
Campaign
Summary
Hide ▲
Show ▼
The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover and cloud data theft. The operation uses social engineering to reset passwords, alter MFA settings, or enroll new devices before attackers pivot into connected SaaS accounts. Recent reporting links the activity to organizations including Medtronic, DentaQuest, iRhythm, and OneMedical.
Related Happenings
Gunra ransomware CVE exploitation and double-extortion activity
Malware Activity
H score26
First: 10.08.2026 15:00
Last: 10.08.2026 15:00
Sources 1
About this happening:
Gunra ransomware is an RaaS operation targeting government and critical national infrastructure organizations, with a joint US/Republic of Korea advisory warni...
Gunra ransomware CVE exploitation and double-extortion activity
Malware ActivityAbout this happening: Gunra ransomware is an RaaS operation targeting government and critical national infrastructure organizations, with a joint US/Republic of Korea advisory warni...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor Meta
H score40
First: 04.08.2026 20:27
Last: 04.08.2026 20:27
Sources 1
About this happening:
Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
Greatness PhaaS expands into device code phishing and integrated token-theft operations
Threat Actor MetaAbout this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...
ShinyHunters social engineering campaign targeting employee SSO accounts
Campaign
H score77
First: 17.07.2026 23:45
Last: 17.07.2026 23:45
Sources 1
How related:
The threat actors are known for identity attacks, where they target employees through social engineering, including vishing and phishing, to compromise corporate single-sign-on accounts.
About this happening:
The ShinyHunters extortion gang is running an ongoing social engineering campaign against employee Microsoft Entra, Okta, and Google SSO accounts, creating a path into...
ShinyHunters social engineering campaign targeting employee SSO accounts
CampaignHow related: The threat actors are known for identity attacks, where they target employees through social engineering, including vishing and phishing, to compromise corporate single-sign-on accounts.
About this happening: The ShinyHunters extortion gang is running an ongoing social engineering campaign against employee Microsoft Entra, Okta, and Google SSO accounts, creating a path into...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor Meta
H score14
First: 13.07.2026 18:30
Last: 13.07.2026 18:30
Sources 1
About this happening:
The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor MetaAbout this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
Helix vishing and SharePoint data-extortion campaign
Campaign
H score38
First: 09.07.2026 20:08
Last: 09.07.2026 20:08
Sources 1
About this happening:
The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Helix vishing and SharePoint data-extortion campaign
CampaignAbout this happening: The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Timeline
-
29.07.2026 20:54 2 articles · 13d ago
ShinyHunters targets healthcare and medtech SSO accounts for cloud data theft
Initial DisclosureHealth-ISAC warned healthcare and medical technology organizations that ShinyHunters is increasing successful social-engineering attacks that compromise single sign-on accounts and steal data from cloud services. The advisory says the group uses vishing and phishing to reset passwords, change MFA methods, or enroll new devices before pivoting into connected SaaS platforms, and recent incident reporting linked activity to Medtronic, DentaQuest, iRhythm, and OneMedical.
Show sources
- Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare — www.bleepingcomputer.com — 29.07.2026 20:54
- Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare — www.bleepingcomputer.com — 29.07.2026 20:54