The ShinyHunters extortion group has taken credit for an active wave of voice phishing (vishing) attacks aimed at single sign-on (SSO) accounts tied to major platforms such as Okta, Microsoft, and Google. Through these attacks, threat actors are able to break into corporate software-as-a-service (SaaS) environments and exfiltrate company data, which is then leveraged for extortion.
Attack Methodology
The campaign follows a deliberate and repeatable playbook that combines social engineering with abuse of authentication workflows. Attackers pose as IT support staff and place phone calls to employees. During these conversations, victims are manipulated into entering their usernames, passwords, and multi-factor authentication (MFA) codes into phishing websites that closely resemble legitimate corporate login pages.
Once credentials are captured, the attackers gain control of the victim’s SSO account. Because SSO is designed to provide centralized access across many services, this single compromise effectively unlocks a wide range of connected enterprise applications and internal systems.
Technical Context of SSO Systems
SSO platforms provided by vendors such as Okta, Microsoft Entra (formerly Azure Active Directory), and Google are commonly used to unify authentication across third-party applications. Employees rely on these systems to access cloud services, internal tools, and business platforms using one set of credentials.
SSO dashboards typically present all linked services in a single interface. When an attacker gains access to an SSO account, this convenience becomes a liability, as it exposes a comprehensive view of accessible corporate resources. Frequently connected services include Salesforce, Microsoft 365, Google Workspace, Dropbox, Adobe, SAP, Slack, Zendesk, and Atlassian products.
The Voice Phishing Process
The attacks begin with phone calls in which threat actors impersonate internal IT personnel. While on the call, they pressure or guide employees into logging into phishing pages and completing MFA challenges in real time.
After securing access to an SSO account, the attackers review the list of connected applications and begin harvesting data from whichever platforms the compromised user can access. Organizations impacted by these intrusions have later received extortion demands signed with the ShinyHunters name, reinforcing attribution to the group.
Industry Response and Technical Analysis
Security news outlet BleepingComputer reached out to Okta earlier in the week regarding the incidents, but the company declined to comment on the alleged data theft. Okta did, however, publish a technical analysis describing the phishing kits used in the vishing campaign, which aligned with information obtained by BleepingComputer from independent sources.
Okta’s analysis indicates that the phishing kits include a web-based control panel that allows attackers to alter phishing pages in real time while speaking with victims. This capability enables threat actors to walk users step by step through the login and MFA process under the guise of legitimate technical assistance.
When stolen credentials are entered into a real service and an MFA challenge is triggered, attackers can instantly update the phishing page to prompt the victim to approve a push notification, provide a time-based one-time password (TOTP), or complete additional authentication steps. This tight synchronization between legitimate services and fraudulent pages significantly increases the success rate of the deception.
ShinyHunters Confirmation and Claims
Although ShinyHunters initially declined to comment, the group later confirmed to BleepingComputer that it was responsible for at least some of the reported social engineering attacks. The group stated that Salesforce is its primary target, with access to other platforms viewed as secondary gains.
ShinyHunters also confirmed several technical details reported by BleepingComputer, including aspects of the phishing infrastructure and domains used. However, the group disputed one point, claiming that a screenshot of a phishing kit command-and-control server shared by Okta did not belong to them and asserting that their tooling was developed internally rather than sourced from third-party providers.
The group stated that its targeting extends beyond Okta to include Microsoft Entra and Google SSO platforms. Microsoft reported that it had no information to share at the time, while Google said it had found no evidence that its products were being abused as part of the campaign. A Google spokesperson noted that there were no indications that Google or its services were affected.
Data Sources and Target Selection
ShinyHunters claims it relies on data obtained from earlier breaches to identify and contact employees. One example cited was large-scale Salesforce-related data theft incidents. The stolen datasets include phone numbers, job titles, names, and other personal details that make impersonation attempts more convincing.
By referencing accurate organizational and role-specific information during calls, attackers increase credibility and reduce the likelihood that targets will recognize the interaction as fraudulent.
Recent Data Leak Site Activity
The group has recently relaunched its Tor-based leak site, which currently lists alleged breaches involving SoundCloud, Betterment, and Crunchbase.
SoundCloud previously disclosed a data breach in December 2025. During the same month, Betterment confirmed that its email platform had been compromised and abused to distribute cryptocurrency scam messages, with data also stolen during the incident.
Crunchbase had not publicly disclosed a breach prior to appearing on the leak site, but later confirmed that data had been taken from its corporate network. A company spokesperson stated that the incident was detected and contained, operations were not disrupted, and systems were secured. Crunchbase also engaged cybersecurity specialists and notified federal law enforcement, adding that it was reviewing the affected data to determine whether regulatory notifications were required.
Security Implications
This campaign underscores the continued evolution of social engineering and demonstrates how even well-secured environments can be compromised when human trust is exploited. The combination of live phone interaction, real-time phishing page manipulation, and personalized data drawn from prior breaches creates a highly effective method for bypassing controls such as MFA.
Organizations relying on SSO should adopt additional safeguards, including targeted employee training on vishing tactics, strict verification procedures for IT support interactions, and enhanced monitoring for anomalous SSO activity. While SSO improves usability and security in many scenarios, its centralized nature also makes it a high-value target, where the compromise of a single account can cascade across multiple enterprise systems.