ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
Campaign
Summary
Hide ▲
Show ▼
The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover and cloud data theft. The operation uses social engineering to reset passwords, alter MFA settings, or enroll new devices before attackers pivot into connected SaaS accounts. Recent reporting links the activity to organizations including Medtronic, DentaQuest, iRhythm, and OneMedical.
Related Happenings
ShinyHunters social engineering campaign targeting employee SSO accounts
Campaign
H score77
First: 17.07.2026 23:45
Last: 17.07.2026 23:45
Sources 1
How related:
The threat actors are known for identity attacks, where they target employees through social engineering, including vishing and phishing, to compromise corporate single-sign-on accounts.
About this happening:
The ShinyHunters extortion gang is running an ongoing social engineering campaign against employee Microsoft Entra, Okta, and Google SSO accounts, creating a path into...
ShinyHunters social engineering campaign targeting employee SSO accounts
CampaignHow related: The threat actors are known for identity attacks, where they target employees through social engineering, including vishing and phishing, to compromise corporate single-sign-on accounts.
About this happening: The ShinyHunters extortion gang is running an ongoing social engineering campaign against employee Microsoft Entra, Okta, and Google SSO accounts, creating a path into...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor Meta
H score14
First: 13.07.2026 18:30
Last: 13.07.2026 18:30
Sources 1
About this happening:
The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor MetaAbout this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
Helix vishing and SharePoint data-extortion campaign
Campaign
H score38
First: 09.07.2026 20:08
Last: 09.07.2026 20:08
Sources 1
About this happening:
The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Helix vishing and SharePoint data-extortion campaign
CampaignAbout this happening: The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Pink new extortion brand within The Com
Threat Actor Meta
H score31
First: 08.07.2026 19:47
Last: 08.07.2026 19:47
Sources 1
About this happening:
Pink is a The Com-linked extortion brand associated with O-UNC-066 that is now being used in a voice-based phishing campaign against Microsoft 365 users. The a...
Pink new extortion brand within The Com
Threat Actor MetaAbout this happening: Pink is a The Com-linked extortion brand associated with O-UNC-066 that is now being used in a voice-based phishing campaign against Microsoft 365 users. The a...
Kali365 Microsoft 365 device-code phishing campaign
Campaign
H score46
First: 25.05.2026 15:45
Last: 25.05.2026 15:45
Sources 1
About this happening:
A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...
Kali365 Microsoft 365 device-code phishing campaign
CampaignAbout this happening: A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...
Timeline
-
29.07.2026 20:54 2 articles · 1h ago
ShinyHunters targets healthcare and medtech SSO accounts for cloud data theft
Initial DisclosureHealth-ISAC warned healthcare and medical technology organizations that ShinyHunters is increasing successful social-engineering attacks that compromise single sign-on accounts and steal data from cloud services. The advisory says the group uses vishing and phishing to reset passwords, change MFA methods, or enroll new devices before pivoting into connected SaaS platforms, and recent incident reporting linked activity to Medtronic, DentaQuest, iRhythm, and OneMedical.
Show sources
- Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare — www.bleepingcomputer.com — 29.07.2026 20:54
- Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare — www.bleepingcomputer.com — 29.07.2026 20:54