Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
Health-ISAC warns healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters, an extortion gang that conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks.
Intelligence analysis by Llama

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare, advising organizations to harden helpdesk and SSO security to prevent attacks. The advisory recommends requiring out-of-band identity verification for password resets, MFA resets, and device re-enrollment requests, and deploying phishing-resistant MFA for administrators and high-risk groups.
Imagine a group of hackers called ShinyHunters who are trying to steal sensitive information from healthcare organizations. They do this by tricking employees into giving them access to important systems, and then using that access to steal data. To prevent this, healthcare organizations need to make sure their helpdesk and security systems are strong and can detect when someone is trying to steal data.
Analysis
ShinyHunters' Attack Pattern
ShinyHunters is an extortion gang that primarily conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks. Over the past two years, the threat actors have become notorious for conducting numerous supply chain attacks on third-party integration partners, giving them access to OAuth tokens that are used to integrate with SaaS providers like Salesforce and Snowflake.
Hardening Helpdesk and SSO Security
According to a July 24 advisory, ShinyHunters attacks follow a chain that begins with voice phishing (vishing) to manipulate employees or helpdesk personnel into resetting passwords, changing multifactor authentication methods, or enrolling new devices. BleepingComputer previously reported that ShinyHunters is using custom phishing kits built for voice-based social engineering (vishing) attacks. These phishing kits are designed for live interaction with targeted employees via voice calls, allowing attackers to change content and display authentication dialogs in real time as a call progresses.
Detecting Cloud Data Theft
Health-ISAC recommends centralizing identity and SaaS audit logs and monitoring for signs of account takeover and large-scale data access, including new MFA registrations, newly enrolled devices, suspicious OAuth grants, unusual API activity, and bulk file downloads. Organizations should also restrict API tokens and third-party integrations, require approval for access to sensitive data, and ensure incident response teams can quickly revoke active sessions, reset credentials, and turn off malicious OAuth applications.
Key points
- Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare organizations
- ShinyHunters conducts supply chain and identity attacks to breach cloud SaaS and storage platforms
- Health-ISAC recommends hardening helpdesk and SSO security to prevent attacks
- Deploying phishing-resistant MFA and monitoring for signs of account takeover and large-scale data access are also recommended
Healthcare organizations can take steps to prevent ShinyHunters data theft attacks by hardening their helpdesk and SSO security, deploying phishing-resistant MFA, and monitoring for signs of account takeover and large-scale data access. By taking these measures, organizations can reduce the risk of data theft and protect sensitive patient information.
If healthcare organizations fail to take steps to prevent ShinyHunters data theft attacks, they risk compromising sensitive patient information and facing significant financial and reputational consequences. The attacks can also lead to a loss of trust in the healthcare sector as a whole.



