ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering

ShinyHunters SSO Vishing Campaign (TL-2026-0013), also tracked as UNC6240, is a critical-severity campaign scored CVSS 9.1, first published 2026-02-02. It is attributed to ShinyHunters with high confidence, affects Okta Okta SSO, maps to 52 MITRE ATT&CK techniques (T1003, T1056, T1059), and is covered by 23 detection rules and 108 indicators of compromise.

Key facts for TL-2026-0013

Threat ID
TL-2026-0013
Also known as
UNC6240, UNC6661, UNC6671, ShinyHunters
Severity
CRITICAL
CVSS
9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N)
Status
ACTIVE
Category
CAMPAIGN
First published
2026-02-02
Last reviewed
2026-02-02
Attribution
ShinyHunters
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
Technology, Financial Services, Retail, Entertainment, Telecommunications, Healthcare, Government, Hospitality, Cloud Services, Cybersecurity
Target regions
Global, North America, Europe, United Kingdom
Detection rules
23
Indicators of compromise
108

Malware and tooling in ShinyHunters SSO Vishing Campaign

Malware and tooling: ALPHV/BlackCat ransomware, ASYNCRAT — .NET backdoor delivered via trojanized .scr files to researchers, ASYNCRAT — .NET backdoor via trojanized .scr files targeting researchers, ASYNCRAT — commercially available .NET backdoor delivered via malicious Windows screensaver files, DragonForce ransomware, ShinySp1d3r RaaS — Hellcat-derived, AI-modified ransomware, ShinySp1d3r RaaS — Hellcat-derived, AI-modified ransomware (Nov 2025), ShinySp1d3r — SLSH ransomware-as-a-service (Hellcat derivative, AI-modified), ULTRAKNOT (Meduza Stealer), VIDAR, ATOMIC, Raccoon Stealer, RattyRAT, AnyDesk, ScreenConnect, Splashtop, TeamViewer, Tailscale, ngrok, EvilProxy / Modlishka / Evilginx MFA relay proxies, Fleetdeck.io, Level.io, Pulseway, RustDesk, Parsec, DWAgent

ShinyHunters (UNC6040/UNC6395/UNC6240) is a prolific English-speaking cybercriminal group operating as part of the 'Scattered LAPSUS$ Hunters' (SLSH) — an amalgamation of ShinyHunters, Scattered Spider, and LAPSUS$. In May 2025, SLSH launched a massive voice phishing (vishing) campaign targeting SSO/MFA to trick victims into connecting malicious apps to their Salesforce portals, siphoning over ONE BILLION records from Salesforce customers. The group operates an extortion website threatening to publish stolen data from 36+ Fortune 500 companies including Toyota, FedEx, Disney/Hulu, and UPS unless ransoms are paid. SLSH also breached Salesloft (AI chatbot maker) stealing authentication tokens for hundreds of cloud services (Snowflake, AWS, Azure, Slack, Google Workspace, OpenAI), breached Red Hat's GitLab server (28,000+ repositories with client secrets), breached Discord user data, and disclosed a zero-day in Oracle E-Business Suite (CVE-2025-61882, pre-auth RCE exploited by Clop). The group launched its own ransomware-as-a-service (ShinySp1d3r, derived from Hellcat ransomware modified with AI) and actively recruits corporate insiders via Telegram. Key operator 'Rey' identified as Saif Al-Din Khader, 15-year-old in Amman, Jordan — previously admin of BreachForums and Hellcat ransomware. Multiple SLSH members arrested: Noah Michael Urban (20, Florida) sentenced 10 years; Thalha Jubair (19, UK) charged for MGM/Caesars/M&S attacks; Tyler Robert Buchanan (23, Scotland) extradited controlling $26M stolen. Law enforcement seized BreachForums domains (FBI, Oct 2025). The group epitomizes 'Advanced Persistent Teenagers' — young, English-speaking cybercriminals causing billions in damage via social engineering, not technical exploitation. Absorbs TL-2026-0030, TL-2026-0045, TL-2026-0054.

How ShinyHunters SSO Vishing Campaign works

ShinyHunters and the Scattered LAPSUS$ Hunters represent the evolution of cybercrime from technical exploitation to SOCIAL ENGINEERING AT SCALE. This is not a sophisticated APT using zero-days — it's teenagers using phone calls, vishing, SIM swapping, and insider recruitment to breach the world's largest corporations.

**The Group — Scattered LAPSUS$ Hunters (SLSH):**

SLSH is an amalgamation of three cybercriminal groups operating from 'the Com' — a mostly English-language cybercriminal community spanning Telegram and Discord servers:

1. **ShinyHunters** (Google: UNC6040) — Data theft and extortion specialists. Responsible for the Salesforce vishing campaign, BreachForums administration, and mass data breaches since 2020. 2. **Scattered Spider** (Google: UNC3944, Microsoft: Octo Tempest) — Social engineering experts targeting corporate helpdesks. Known for MGM Resorts, Caesars Entertainment, and dozens of other breaches via SIM swapping and MFA fatigue. 3. **LAPSUS$** — The original 'Advanced Persistent Teenagers' group that breached Microsoft, Nvidia, Samsung, Uber, and Okta in 2021-2022.

Members overlap significantly and operate across shared Telegram/Discord channels on the Com.

**The Salesforce Vishing Campaign (May 2025):**

The flagship SLSH operation of 2025: - Voice phishing (vishing) calls to employees at target companies - Social engineering targets into connecting malicious OAuth apps to their organization's Salesforce portal - Siphoned over 1 BILLION records from Salesforce customer instances - Google Threat Intelligence Group (GTIG) warned in June 2025 - Google itself was impacted — their own corporate Salesforce instance was compromised - 36+ Fortune 500 companies had data stolen: Toyota, FedEx, Disney/Hulu, UPS, and more - Data leak website launched October 2025: 'Scattered LAPSUS$ Hunters' blog threatening publication - Group demanded Salesforce pay a single ransom to protect ALL customers: 'If we come to a resolution all individual extortions against your customers will be withdrawn' - Salesforce refused: 'Salesforce will not engage, negotiate with, or pay any extortion demand'

**The Salesloft Breach (August 2025):**

A separate but connected SLSH operation (tracked as UNC6395): - Compromised Salesloft, an AI chatbot maker used by many corporations to convert customer interactions into Salesforce leads - Stole authentication tokens for hundreds of cloud services integrated with Salesloft - Affected services: Snowflake, Amazon AWS, Microsoft Azure, Slack, Google Workspace, Docker, OpenAI - Google warned the breach 'goes far beyond Salesforce data' - Hundreds more organizations affected beyond the initial Salesforce campaign

**Red Hat GitLab Breach (September 2025):**

- Compromised Red Hat's consulting GitLab server - Stole 28,000+ Git code repositories - 5,000+ Customer Engagement Reports (CERs) containing client secrets - Exposed: Artifactory tokens, Git tokens, Azure credentials, Docker credentials, client infrastructure details, audit reports - Red Hat disclosed October 2, 2025

**Discord Breach (September 2025):**

- Compromised third-party customer service provider used by Discord - Stole usernames, emails, IP addresses, last 4 digits of payment cards, government ID images from age verification - Discord began notifying affected users

**Oracle Zero-Day (CVE-2025-61882):**

- SLSH's extortion blog disclosed a critical zero-day in Oracle E-Business Suite - Unauthenticated remote code execution - Initially exploited in August 2025 by Clop ransomware - Oracle issued emergency patch - SLSH published exploitation scripts on their blog before it was taken down

**ShinySp1d3r Ransomware-as-a-Service:**

- SLSH launched its own RaaS in November 2025 - Derived from Hellcat ransomware source code, modified with AI tools - Released by Rey (Saif Al-Din Khader) - Previously used other groups' encryptors: ALPHV/BlackCat, Qilin, RansomHub, DragonForce

**Corporate Insider Recruitment:**

- SLSH actively recruits insiders via Telegram: employees at large companies who share internal access for a share of ransom payment - CrowdStrike fired an employee for allegedly sharing screenshots of internal systems with the group - Insider recruitment = bypassing ALL technical security controls

**Key Operator — Rey / Saif Al-Din Khader:**

- Real name: Saif Al-Din Khader, 15 years old, Amman, Jordan - Admin of SLSH Telegram channel, BreachForums, and Hellcat ransomware site - Previously operated as 'Hikki-Chan' and 'o5tdev' on cybercrime forums - Part of Cyb3r Drag0nz Team (pro-Palestinian hacktivist group) - Identified via infostealer data from his own infected family PC - Father is Royal Jordanian Airlines pilot; Irish heritage (mother's maiden name Ginty) - Claimed to be cooperating with European law enforcement since June 2025

**Law Enforcement Actions:**

- Noah Michael Urban, 20, Florida — sentenced 10 years, $13M restitution (Aug 2025) - Thalha Jubair, 19, UK — charged for MGM/Caesars/M&S/Harrods/Co-op attacks, LAPSUS$ member - Tyler Robert Buchanan, 23, Scotland — extradited from Spain, controlled $26M stolen - BreachForums domains seized by FBI (October 5, 2025) - Operation Endgame targeting cybercrime services

**Absorbs Duplicates:** - TL-2026-0030: ShinyHunters data breach operations - TL-2026-0045: Scattered Spider social engineering TTPs - TL-2026-0054: LAPSUS$/vishing campaign analysis

MITRE ATT&CK techniques used in TL-2026-0013

credential-access

T1003 OS Credential Dumping; T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores; T1556 Modify Authentication Process; T1557 Adversary-in-the-Middle; T1606 Forge Web Credentials; T1621 Multi-Factor Authentication Request Generation

collection

T1056 Input Capture; T1074 Data Staged; T1114 Email Collection; T1119 Automated Collection; T1213 Data from Information Repositories; T1530 Data from Cloud Storage

execution

T1059 Command and Scripting Interpreter; T1204 User Execution

defense-evasion

T1078 Valid Accounts

discovery

T1082 System Information Discovery; T1087 Account Discovery; T1526 Cloud Service Discovery; T1538 Cloud Service Dashboard; T1580 Cloud Infrastructure Discovery; T1619 Cloud Storage Object Discovery

persistence

T1098 Account Manipulation; T1136 Create Account

initial-access

T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing

command-and-control

T1219 Remote Access Tools

defense-impairment

T1484 Domain or Tenant Policy Modification; T1685 Disable or Modify Tools

impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1657 Financial Theft

exfiltration

T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service

lateral-movement

T1550 Use Alternate Authentication Material

resource-development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities

reconnaissance

T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information; T1593 Search Open Websites/Domains; T1594 Search Victim-Owned Websites; T1596 Search Open Technical Databases; T1597 Search Closed Sources; T1598 Phishing for Information

stealth

T1684.001 Impersonation

Affected products and versions in ShinyHunters SSO Vishing Campaign

  • Okta — Okta SSO
    Vulnerable versions: All - social engineering
  • Microsoft — Entra ID (Azure AD)
    Vulnerable versions: All - social engineering
  • Google — Google Workspace SSO
    Vulnerable versions: All - social engineering
  • Salesforce — Salesforce
    Vulnerable versions: All - via SSO

Remediation for ShinyHunters SSO Vishing Campaign

Immediate actions

  • Alert employees about vishing attacks impersonating IT staff
  • Implement callback verification for all MFA reset requests
  • Review recent MFA enrollments for unauthorized devices
  • Audit OAuth app authorizations in Google Workspace
  • Check for ToogleBox Recall installation

Workarounds

  • Establish verbal password/PIN for IT helpdesk calls
  • Require in-person verification for MFA changes
  • Block known phishing domain patterns at DNS/proxy

Longer-term hardening

  • Require phishing-resistant MFA (FIDO2/WebAuthn) instead of push/OTP
  • Implement number matching for MFA push notifications
  • Deploy conditional access policies based on device compliance
  • Enable continuous access evaluation in Azure AD
  • Restrict OAuth app authorizations to approved list

Weaknesses (CWE) in ShinyHunters SSO Vishing Campaign

CWE-287, CWE-352, CWE-601

Timeline of ShinyHunters SSO Vishing Campaign

  • ShinyHunters emerges as a data breach and extortion group. Initial operations focus on compromising databases and selling stolen data on dark web forums. The group builds a reputation for high-volume data theft from technology companies, eventually accumulating breaches affecting hundreds of millions of records. Operates primarily through BreachForums and Telegram.
  • LAPSUS$ group emerges, breaching Microsoft, Nvidia, Samsung, Uber, Okta, and other major technology companies. Uses social engineering, SIM swapping, and insider recruitment. Members are primarily teenagers. Several members identified and arrested, including a 16-year-old in the UK. Establishes the 'Advanced Persistent Teenagers' paradigm — young hackers causing billions in damage.
  • Scattered Spider (UNC3944/Octo Tempest) emerges targeting corporate helpdesks with social engineering. Group would go on to breach MGM Resorts ($100M+ impact), Caesars Entertainment ($15M ransom paid), and dozens of other companies. Uses SIM swapping, MFA fatigue, and vishing. Members overlap with LAPSUS$ and ShinyHunters on the Com.
  • Rey (Saif Al-Din Khader, then 14 years old) becomes active on BreachForums as 'Hikki-Chan' and 'o5tdev'. Posts stolen CDC data. Takes over as admin of BreachForums and Hellcat ransomware site. Previously part of Cyb3r Drag0nz Team (pro-Palestinian hacktivism). Will become the public face and technical operator of SLSH.
  • Cybersecurity firm KELA unmasks Hellcat ransomware operators including Rey (Saif Al-Din Khader) through analysis of infostealer data from his own infected family PC. His unique password from a sextortion scam screenshot linked his Telegram handle to his real identity. Age 15, located in Amman, Jordan. Father is Royal Jordanian Airlines pilot. Source: https://www.kelacyber.com/blog/hellcat-hacking-group-unmasked-rey-and-pryx/
  • SLSH launches massive voice phishing campaign targeting Salesforce customers. Social engineering employees via phone calls to trick them into connecting malicious OAuth apps to their organization's Salesforce portals. Over 1 BILLION records siphoned. 36+ Fortune 500 companies affected including Toyota, FedEx, Disney/Hulu, UPS. Google's own corporate Salesforce instance compromised. Source: https://cloud.google.com/blog/topics/threat-intelligence/voice-phishing-data-extortion
  • SLSH (tracked as UNC6395) compromises Salesloft, an AI chatbot maker whose product integrates with hundreds of cloud services. Steals authentication tokens for Snowflake, AWS, Azure, Slack, Google Workspace, Docker, OpenAI. Google warns breach 'goes far beyond Salesforce data.' Hundreds of additional organizations affected. Source: https://krebsonsecurity.com/2025/09/the-ongoing-fallout-from-a-breach-at-ai-chatbot-maker-salesloft/
  • Noah Michael Urban, 20, convicted Scattered Spider member from Florida, sentenced to 10 years in federal prison and ordered to pay $13 million in restitution to victims. First major sentencing of a Scattered Spider member. Source: https://krebsonsecurity.com/2025/08/sim-swapper-scattered-spider-hacker-gets-10-years/
  • ShinyHunters breaches Discord's third-party customer service provider (usernames, emails, IPs, partial payment cards, government IDs). Separately, Red Hat discloses compromise of their consulting GitLab server — 28,000+ repositories, 5,000+ CERs with client secrets (Artifactory tokens, Git tokens, Azure/Docker creds). Source: https://www.redhat.com/en/blog/security-update-incident-related-red-hat-consulting-gitlab-instance
  • UK prosecutors charge Thalha Jubair (19) and another for extorting $115M+ in ransoms. Jubair linked to MGM Resorts, Caesars, Marks & Spencer, Harrods, Co-op Group attacks and was LAPSUS$ member. Tyler Robert Buchanan (23, Scotland) extradited from Spain — controlled $26M stolen. Source: https://krebsonsecurity.com/2025/09/feds-tie-scattered-spider-duo-to-115m-in-ransoms/
  • FBI seizes BreachForums domains (again). SLSH extortion blog discloses Oracle E-Business Suite zero-day (CVE-2025-61882, unauthenticated RCE) — published exploitation scripts before blog was taken down. Oracle confirms the vulnerability and issues emergency patch. CVE was exploited since August by Clop ransomware. SLSH blog goes offline after shifting DNS to Cloudflare. Source: https://www.oracle.com/security-alerts/alert-cve-2025-61882.html
  • KrebsOnSecurity tracks down Rey (Saif Al-Din Khader, 15, Amman, Jordan) and interviews him after contacting his father. Rey confirms identity, claims to be cooperating with European law enforcement since June. SLSH launches ShinySp1d3r RaaS (Hellcat-derived, AI-modified). Group recruits insiders via Telegram — CrowdStrike fires employee for sharing internal screenshots with SLSH. Source: https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-scattered-lapsus-hunters/
  • Ongoing: SLSH continues to operate despite arrests and takedowns. ShinySp1d3r RaaS active. Insider recruitment ongoing. Salesloft token fallout continues as organizations discover compromised cloud service credentials. The 'Advanced Persistent Teenagers' paradigm is now the dominant cybercrime model — social engineering at scale by young, English-speaking actors causing more damage than most state-sponsored groups. Revalidation absorbs TL-2026-0030, TL-2026-0045, TL-2026-0054.
  • As of 2026-05-29, ShinyHunters/Scattered LAPSUS$ Hunters remains fully ACTIVE — an FBI IC3 PSA (May 15, 2026) plus fresh confirmed breaches of Charter, Instructure Canvas (275M records, May 7-12), and 7-Eleven (185K, May 26). Affiliate arrests and BreachForums seizures have not disrupted the decentralized group, which has pivoted to a new March 2026 Salesforce Experience Cloud/AuraInspector vishing campaign.

Sources cited for ShinyHunters SSO Vishing Campaign

Threats related to ShinyHunters SSO Vishing Campaign

Detection coverage for TL-2026-0013

As of 2026-02-02, Threadlinqs Intelligence publishes 23 detection rule(s) for TL-2026-0013 across Splunk SPL, Microsoft KQL and Sigma, covering 108 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats