ShinyHunters-Branded Extortion Campaign Expands with Vishing & SSO Attacks

ShinyHunters-Branded Extortion Campaign Expands with Vishing (TL-2026-0045), also tracked as ShinyHunters, is a high-severity tracked threat-actor profile scored CVSS 8.2, first published 2026-02-03. It is attributed to ShinyHunters (France) with high confidence, affects Multiple Enterprise SSO Systems (Okta, Azure AD, Google Workspace), maps to 42 MITRE ATT&CK techniques (T1036, T1056, T1070), and is covered by 15 detection rules and 46 indicators of compromise.

Key facts for TL-2026-0045

Threat ID
TL-2026-0045
Also known as
ShinyHunters, SH Extortion Group
Severity
HIGH
CVSS
8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N)
Status
ACTIVE
Category
THREAT_ACTOR
First published
2026-02-03
Last reviewed
2026-02-03
Attribution
ShinyHunters
Attribution confidence
HIGH
Nation-state nexus
France
Motivation
FINANCIAL
Target sectors
Technology, Telecommunications, Financial Services, Entertainment/Hospitality, Healthcare, Retail, Cloud Services, Social Media
Target regions
North America, Europe, Global
Detection rules
15
Indicators of compromise
46

ShinyHunters-branded extortion campaign leveraging voice phishing (vishing) and SSO credential theft as primary attack vectors. Distinct from TL-0030 (parent ShinyHunters evolved vishing overview) and TL-0013 (SLSH/ShinyHunters credential marketplace). This threat focuses on the specific vishing TTPs and fake SSO portal mechanics: phone-based pretexting to helpdesk and remote employees, real-time MFA relay via custom phishing pages, SSO portal impersonation for Okta/Azure AD/Google Workspace, and the operational model of 'The Com' — the distributed cybercriminal social network enabling instant collaboration between vishing operators, credential harvesters, and data extortionists. Linked to UNC5537 (Mandiant), Scattered Spider (CrowdStrike), and the Beige Group. The campaign exploits the post-COVID remote work landscape where VPN/SSO portals are the new perimeter.

How ShinyHunters-Branded Extortion Campaign Expands with Vishing works

This threat profile covers the ShinyHunters-branded extortion campaign's specific use of voice phishing (vishing) and SSO credential theft — the operational TTPs that enabled breaches of 160+ Snowflake customer organizations, the MGM Resorts casino shutdown, and ongoing corporate extortion campaigns.

Vishing Operations Model: The campaign operates through 'The Com' — a distributed archipelago of Telegram and Discord channels functioning as a cybercriminal social network. Operators work in coordinated pairs: one caller conducts the social engineering over the phone while a second operator simultaneously uses stolen credentials at the phishing page in real-time. This two-person relay defeats time-based MFA because the one-time code is captured and replayed within its validity window (typically 30-60 seconds).

Vishing TTPs (7 distinct techniques): 1. IT Helpdesk Impersonation: Callers pose as company IT department staff troubleshooting VPN issues. They use company-specific terminology learned from previous failed calls, building a progressively more convincing pretext with each attempt. Target: remote employees. 2. New Hire Pretexting: Attackers create LinkedIn profiles as fake new employees and connect with real employees to build legitimacy. When they call claiming to be from IT, the target can verify the 'employee' exists on LinkedIn/Teams/Slack. 3. MFA Relay in Real-Time: Custom phishing pages request the MFA token alongside username/password. The second operator enters the credentials at the real login portal within seconds, before the time-based code expires. 4. New Hire Targeting: Focused reconnaissance on recently hired employees who are less familiar with company procedures, IT contacts, and security protocols. New hires are statistically more likely to comply with 'IT department' requests. 5. Progressive Reconnaissance: Each failed vishing attempt teaches the attackers more about internal operations — corporate lingo, organizational structure, tool names, employee names. They iterate and improve with each call. 6. Domain Activation/Deactivation: Phishing domains are registered and configured but remain offline until the vishing call begins. The site goes live only during the active call, then is immediately disabled. This defeats abuse reporting that requires a live phishing page. 7. Phone Number Spoofing: Caller ID spoofed to appear as the target company's actual helpdesk number, adding legitimacy to the pretext.

SSO Portal Attacks: The campaign maintains a factory of fake SSO portals impersonating Okta, Azure AD, Google Workspace, Duo Security, and corporate VPN login pages. Domain naming follows a predictable pattern: [company]-vpn[.]com, [company]-sso[.]com, helpdesk-[company][.]com, [company]-portal[.]com, [company]-employee[.]com, [company]-ticket[.]com. These pages are pixel-perfect clones with working links to legitimate internal resources, making them nearly indistinguishable from authentic login portals. The pages include: - Real corporate branding and logos scraped from public sites - Working links to real company resources (HR portal, benefits, intranet) - MFA prompt that captures and relays the one-time code in real-time - Session token capture for post-authentication lateral movement - Custom SSL certificates from Let's Encrypt for the green padlock

The Com Ecosystem: The broader ecosystem fueling these attacks is 'The Com' — a distributed cybercriminal social network operating across Telegram and Discord. Key characteristics: - Bounty system: customers pay operators to target specific companies - Leaderboards: ranked by stolen cryptocurrency holdings and successful hacks - Specialization: SIM swappers, vishers, phishing page builders, and data brokers collaborate - Youth recruitment: many operators are teenagers (the MGM hacker was 17, LAPSUS$ member at 15) - Cross-pollination: members move between cybercrime and harm communities (764, CVLT, Leak Society) - Brand fluidity: same actors operate under Scattered Spider, ShinyHunters, LAPSUS$, Beige Group, UNC5537 labels

Snowflake Campaign (UNC5537): The vishing and SSO credential theft directly enabled the Snowflake campaign, where attackers discovered that major corporations stored massive datasets on Snowflake servers protected only by username/password (no MFA). Using credentials obtained via vishing, phishing, and darknet marketplace purchases, UNC5537 breached 160+ organizations including AT&T (110M customer records), TicketMaster, Lending Tree, Advance Auto Parts, Neiman Marcus, and Santander Bank. Private extortion demands were made before public breach disclosure.

MGM Resorts Attack: The September 2023 MGM casino shutdown — one of the most high-profile cyberattacks in history — began with a single vishing call. A 17-year-old Scattered Spider member called MGM tech support, impersonated an employee, and convinced them to reset an account password. This single social engineering call led to ALPHV/BlackCat ransomware deployment, a week-long casino shutdown, and an estimated $100M+ in losses.

Evolution Timeline: - 2020: Beige Group pioneers corporate VPN vishing during COVID-19 remote work transition - 2020: GoDaddy employees social engineered into installing malware via phone calls - 2021-2022: LAPSUS$ teenage hackers breach EA, Microsoft, NVIDIA, Okta, Samsung, T-Mobile via social engineering - 2023: Scattered Spider/ALPHV attack on MGM Resorts via single vishing call - 2023-2024: UNC5537 Snowflake campaign — 160+ orgs breached using stolen credentials - 2024: ShinyHunters brand adopted for extortion campaigns using same vishing infrastructure - 2025-2026: Campaign continues with refined SSO portal attacks and expanded targeting

Key Insight: The entire ShinyHunters extortion empire is built on social engineering, not technical exploitation. There are no zero-days, no malware (initially), no network intrusion. A phone call to the right person with the right pretext is sufficient to compromise any organization that relies on SSO/VPN as its security perimeter.

MITRE ATT&CK techniques used in TL-2026-0045

defense-evasion

T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts; T1684.001 Impersonation

collection

T1056 Input Capture; T1074 Data Staged; T1213 Data from Information Repositories; T1530 Data from Cloud Storage

command-and-control

T1071 Application Layer Protocol

discovery

T1087 Account Discovery; T1526 Cloud Service Discovery; T1580 Cloud Infrastructure Discovery; T1619 Cloud Storage Object Discovery

persistence

T1098 Account Manipulation; T1098.001 Additional Cloud Credentials

initial-access

T1199 Trusted Relationship; T1566 Phishing; T1566.004 Spearphishing Voice

execution

T1204 User Execution

impact

T1486 Data Encrypted for Impact; T1531 Account Access Removal; T1565 Data Manipulation; T1657 Financial Theft

credential-access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1556 Modify Authentication Process; T1557 Adversary-in-the-Middle; T1606 Forge Web Credentials; T1621 Multi-Factor Authentication Request Generation

exfiltration

T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service

lateral-movement

T1550 Use Alternate Authentication Material

resource-development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities

reconnaissance

T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information; T1593 Search Open Websites/Domains; T1594 Search Victim-Owned Websites

Affected products and versions in ShinyHunters-Branded Extortion Campaign Expands with Vishing

  • Multiple — Enterprise SSO Systems (Okta, Azure AD, Google Workspace)
    Vulnerable versions: All - social engineering attack

Remediation for ShinyHunters-Branded Extortion Campaign Expands with Vishing

Patches

  • N/A — This is a social engineering campaign, not a software vulnerability. Defense requires procedural and architectural controls.

Immediate actions

  • Implement mandatory callback verification for ALL helpdesk password reset and MFA reset requests — call the employee back on a known number, never trust the inbound caller
  • Deploy phishing-resistant MFA (FIDO2/WebAuthn hardware security keys) for all SSO and VPN access — time-based OTP is defeated by real-time relay
  • Establish a verbal passphrase or PIN system for IT helpdesk interactions that cannot be socially engineered from public information
  • Alert all employees about vishing attacks — particularly new hires who are the primary target
  • Audit all Snowflake and cloud data platform accounts for MFA enforcement — single-factor accounts are immediately vulnerable

Workarounds

  • Restrict helpdesk ability to reset MFA or passwords without multi-person approval
  • Block all VPN/SSO access from known VPN/proxy exit nodes used by attackers
  • Implement geographic restrictions on SSO authentication based on employee location
  • Require video verification for sensitive helpdesk operations

Longer-term hardening

  • Implement number-matching MFA (push notifications that require entering a number displayed on screen) to defeat real-time phishing relay
  • Deploy FIDO2/WebAuthn across the organization as the primary MFA method — immune to phishing and real-time relay
  • Establish dedicated, verified communication channels between IT and employees that attackers cannot impersonate
  • Implement continuous SSO domain monitoring — detect typosquat and impersonation domains before they are activated
  • Train helpdesk staff on social engineering resistance with regular red team vishing exercises
  • Enforce Conditional Access policies: block SSO access from unmanaged devices, unfamiliar locations, and suspicious IP ranges
  • Implement impossible travel detection for SSO logins — flag logins from geographically impossible locations within short timeframes
  • Establish out-of-band verification for all privileged account changes (password resets, MFA resets, role changes)

Weaknesses (CWE) in ShinyHunters-Branded Extortion Campaign Expands with Vishing

CWE-287, CWE-306

Timeline of ShinyHunters-Branded Extortion Campaign Expands with Vishing

  • COVID-19 forces mass remote work transition. Corporate VPNs and SSO portals become the new security perimeter. Attack surface for vishing explodes as employees work from home on personal devices.
  • KrebsOnSecurity reports on Beige Group vishing attacks targeting corporate VPN credentials. Two-person relay teams defeat MFA in real-time. Phishing domains activated only during active calls to avoid takedowns. Source: https://krebsonsecurity.com/2020/08/voice-phishers-targeting-corporate-vpns/
  • Beige Group social engineers GoDaddy employees into installing malware via phone calls, redirecting web and email traffic for cryptocurrency platforms. Source: https://krebsonsecurity.com/2020/11/godaddy-employees-used-in-attacks-on-multiple-cryptocurrency-services/
  • LAPSUS$ teenage hackers breach EA, Microsoft, NVIDIA, Okta, Samsung, T-Mobile via social engineering and SIM swapping. Key member (later arrested for MGM hack) was 15 years old. Demonstrates youth recruitment pipeline in The Com.
  • 0ktapus phishing campaign compromises 130+ organizations via fake Okta SSO portals, harvesting 10,000+ credentials. Template-based approach enables rapid deployment of company-specific phishing sites.
  • Scattered Spider/ALPHV attack on MGM Resorts. A single vishing call to MGM tech support by a 17-year-old UK-based attacker triggers casino-wide shutdown, ransomware deployment, and estimated $100M+ losses. The most high-profile social engineering attack in history.
  • UNC5537 discovers that major corporations store massive datasets on Snowflake protected only by username/password (no MFA). Begin purchasing stolen Snowflake credentials from darknet markets and using vishing-obtained credentials.
  • User 'Judische' (later identified as UNC5537 member) claims Santander Bank breach on Star Chat Telegram channel. First known Snowflake victim publicly linked to this campaign.
  • Mandiant publishes UNC5537 report: 160+ Snowflake customer organizations breached. Attackers used stolen credentials (from vishing, phishing, and darknet purchases) against accounts without MFA. Private extortion before public disclosure.
  • AT&T discloses that 110M customer records (phone + SMS records for nearly ALL customers) stolen via Snowflake breach. Largest single data breach by record count in the campaign.
  • West Midlands Police (UK) arrests 17-year-old 'Holy' in joint operation with FBI. The teenager who made the MGM vishing call was also linked to LAPSUS$ (as 'Vsphere' at age 15) and harm communities (764, Leak Society). Source: https://www.westmidlands.police.uk/news/west-midlands/news/news/2024/july/walsall-teenager-arrested-in-joint-west-midlands-police-and-fbi-operation/
  • CISA publishes advisory AA24-242a on Scattered Spider: social engineering, MFA bypass via real-time relay, SIM swapping, and ALPHV/BlackCat ransomware partnership. Emphasizes vishing as primary initial access vector.
  • KrebsOnSecurity publishes 'The Dark Nexus Between Harm Groups and The Com' exposing overlap between Scattered Spider/ShinyHunters cybercrime and harm communities targeting minors. Same actors operate across both domains. Source: https://krebsonsecurity.com/2024/09/the-dark-nexus-between-harm-groups-and-the-com/
  • ShinyHunters brand increasingly used for extortion campaigns leveraging the same vishing and SSO phishing infrastructure. Brand fluidity: same actors cycle through Scattered Spider, ShinyHunters, LAPSUS$, Beige Group identities.
  • Campaign continues with refined SSO portal attacks targeting Okta, Azure AD, Google Workspace. Real-time MFA relay defeats time-based OTP. Phishing-resistant MFA (FIDO2/WebAuthn) is the only effective technical defense.
  • Threadlinqs Intelligence analysis: ShinyHunters vishing + SSO attacks distinct from TL-0030 (parent overview) and TL-0013 (credential marketplace). Focus on vishing TTPs, SSO portal mechanics, The Com operational model, and the social engineering kill chain that requires zero technical vulnerabilities.
  • As of 2026-05-29, TL-2026-0045 is still active: ShinyHunters published ~13M Charter/Spectrum records around May 27-29 after a vishing-to-Entra-SSO Salesforce breach, amid a 2026 wave hitting Instructure, Panera, Aura, and ADT. The decentralized actor survived 2026 arrests undisrupted, no CVE applies, and no successor supersedes it.

Sources cited for ShinyHunters-Branded Extortion Campaign Expands with Vishing

Threats related to ShinyHunters-Branded Extortion Campaign Expands with Vishing

Detection coverage for TL-2026-0045

As of 2026-02-03, Threadlinqs Intelligence publishes 15 detection rule(s) for TL-2026-0045 across Splunk SPL, Microsoft KQL and Sigma, covering 46 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats