discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

Health-ISAC warns healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters, an extortion gang that conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks.

By Lawrence Abrams·Jul 29·bleepingcomputer.com·2 min read

Intelligence analysis by Llama

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
Image: bleepingcomputer.com

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare, advising organizations to harden helpdesk and SSO security to prevent attacks. The advisory recommends requiring out-of-band identity verification for password resets, MFA resets, and device re-enrollment requests, and deploying phishing-resistant MFA for administrators and high-risk groups.

Why it matters

The rising ShinyHunters data theft attacks on healthcare organizations pose a significant threat to patient data and medical technology, highlighting the need for robust security measures to prevent such attacks.

Imagine a group of hackers called ShinyHunters who are trying to steal sensitive information from healthcare organizations. They do this by tricking employees into giving them access to important systems, and then using that access to steal data. To prevent this, healthcare organizations need to make sure their helpdesk and security systems are strong and can detect when someone is trying to steal data.

Analysis

ShinyHunters' Attack Pattern

ShinyHunters is an extortion gang that primarily conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks. Over the past two years, the threat actors have become notorious for conducting numerous supply chain attacks on third-party integration partners, giving them access to OAuth tokens that are used to integrate with SaaS providers like Salesforce and Snowflake.

Hardening Helpdesk and SSO Security

According to a July 24 advisory, ShinyHunters attacks follow a chain that begins with voice phishing (vishing) to manipulate employees or helpdesk personnel into resetting passwords, changing multifactor authentication methods, or enrolling new devices. BleepingComputer previously reported that ShinyHunters is using custom phishing kits built for voice-based social engineering (vishing) attacks. These phishing kits are designed for live interaction with targeted employees via voice calls, allowing attackers to change content and display authentication dialogs in real time as a call progresses.

Detecting Cloud Data Theft

Health-ISAC recommends centralizing identity and SaaS audit logs and monitoring for signs of account takeover and large-scale data access, including new MFA registrations, newly enrolled devices, suspicious OAuth grants, unusual API activity, and bulk file downloads. Organizations should also restrict API tokens and third-party integrations, require approval for access to sensitive data, and ensure incident response teams can quickly revoke active sessions, reset credentials, and turn off malicious OAuth applications.

Key points

  • Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare organizations
  • ShinyHunters conducts supply chain and identity attacks to breach cloud SaaS and storage platforms
  • Health-ISAC recommends hardening helpdesk and SSO security to prevent attacks
  • Deploying phishing-resistant MFA and monitoring for signs of account takeover and large-scale data access are also recommended
The Upside

Healthcare organizations can take steps to prevent ShinyHunters data theft attacks by hardening their helpdesk and SSO security, deploying phishing-resistant MFA, and monitoring for signs of account takeover and large-scale data access. By taking these measures, organizations can reduce the risk of data theft and protect sensitive patient information.

The Downside

If healthcare organizations fail to take steps to prevent ShinyHunters data theft attacks, they risk compromising sensitive patient information and facing significant financial and reputational consequences. The attacks can also lead to a loss of trust in the healthcare sector as a whole.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityhealthcareshinyhuntersdata-theftcloud-security

Author

Lawrence Abrams

Intelligence analysis by

Llama

Published

Jul 29, 2026

Source

bleepingcomputer.com

Share

Topics

securityhealthcareshinyhuntersdata-theftcloud-security

Related

More from this desk

Jul 29·thehackernews.com

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

A critical Active Storage vulnerability in Ruby on Rails allows unauthenticated attackers to read arbitrary files from application servers through crafted image uploads. The flaw, tracked as CVE-2026-66066, can expose secrets such as secret_key_base, the Rails master key,…

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…