• 07 3184 7575
  • August 31, 2026
  • 0 Comments

We recently came across reporting from SecurityWeek about a large-scale cybercrime campaign linked to the ShinyHunters group. Given the number of well-known organisations mentioned and the techniques involved, we believe this is an important development to share — particularly for businesses relying on single sign-on (SSO) and multi-factor authentication (MFA) platforms.

According to security firm Silent Push, threat actors appear to have prepared or conducted attacks targeting at least 100 organisations over the past 30 days. The sectors potentially affected include software and technology, finance, biotech, healthcare, energy, logistics, manufacturing, retail, and insurance.

Several major companies were named in the research, including Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos, and Telstra. At this stage, it remains unclear whether all listed organisations were successfully compromised, but domains designed to impersonate these companies were identified.

How the Attack Works: Vishing Meets Real-Time MFA Bypass

The campaign reportedly relied on voice phishing (vishing) to target single sign-on (SSO) accounts connected to platforms such as Okta and other identity providers.

In observed incidents, attackers used specialised phishing kits capable of intercepting credentials while simultaneously guiding victims over the phone.

Okta described one of the most concerning elements as the use of client-side scripts that allow attackers to control the authentication flow in real time. This enables them to:

  • Intercept usernames and passwords
  • Trigger MFA prompts
  • Instruct victims verbally to approve push notifications
  • Collect one-time passcodes (OTP)
  • Or guide them through other steps needed to bypass MFA

Because the attack unfolds live — with attackers reacting to user actions in real time — it can appear convincing and legitimate.

This is not a software vulnerability in Okta itself. It is a social engineering technique that exploits human behaviour within otherwise secure systems.

Who Is Behind the Campaign?

Although the name ShinyHunters has been used publicly, Silent Push attributes the activity — based on tactics, techniques, and procedures (TTPs) — to a broader group known as Scattered LAPSUS$ Hunters, reportedly formed by members associated with Lapsus$, Scattered Spider, and ShinyHunters.

On the ShinyHunters leak site, companies such as Betterment, Crunchbase, and SoundCloud were listed, and those organisations have confirmed experiencing data breaches.

Threat intelligence firm Hudson Rock indicated that some of these incidents were tied to the Okta SSO vishing campaign. Google’s Mandiant has also described the activity as active and ongoing.

After gaining initial access, the attackers reportedly pivoted into SaaS environments to exfiltrate sensitive data. In some cases, organisations were approached with extortion demands.

Why This Matters

This campaign highlights an important shift in attacker behaviour.

Rather than exploiting technical vulnerabilities, attackers are increasingly focusing on:

  • Real-time social engineering
  • Identity platforms
  • MFA fatigue or push approval abuse
  • Credential interception combined with human manipulation

In many environments, SSO and MFA are considered strong defensive controls. However, when attackers combine phishing kits with live voice interaction, even well-implemented MFA can be bypassed.

Recommended Defensive Measures

Charles Carmakal, CTO of Mandiant Consulting, recommends moving toward phishing-resistant MFA, such as:

  • FIDO2 security keys
  • Passkeys

These authentication methods are significantly more resistant to social engineering compared to push-based or SMS-based MFA.

He also recommends:

  • Strict application authorisation policies
  • Monitoring logs for anomalous API activity
  • Monitoring for unauthorised device enrolments

These measures help reduce the window of opportunity after initial compromise.

A CSB Perspective

At CSB, we see a clear pattern emerging: identity is becoming the primary attack surface.

Modern cyberattacks are no longer solely about malware delivery. They are about convincing legitimate users to grant access.

Organisations should consider:

  • Reviewing their MFA configuration and approval flows
  • Limiting push-based MFA where possible
  • Implementing phishing-resistant authentication for high-risk accounts
  • Training staff on vishing and live MFA manipulation tactics
  • Monitoring identity platform logs proactively

Strong authentication is still essential — but authentication alone is not enough without visibility and behavioural monitoring.

The most effective defence today combines:

  • Phishing-resistant MFA
  • Conditional access policies
  • Real-time monitoring
  • Staff awareness
  • Incident response readiness

Cybersecurity is increasingly about reducing the success rate of social engineering, not just blocking technical exploits.

Previous Post
Hundreds of Chrome Extensions Found Leaking Data — Why This Matters for Your Organisation