Skip to content
feed: live
>_ 0dayNews
ransomware

ShinyHunters Targets Healthcare SSO, Health-ISAC Warns

Health-ISAC warns healthcare orgs of rising ShinyHunters attacks using SSO social engineering to compromise cloud accounts and steal data.

ShinyHunters Targets Healthcare SSO, Health-ISAC Warns
Image: 0dayNews / 0dayNews Editorial · All rights reserved
fuse Marisol "Fuse" Delgado · Published · 2 min read

Health-ISAC issued a warning Tuesday about ShinyHunters, citing an observed increase in successful attacks against healthcare and medical technology organizations. Attack method: social engineering to compromise SSO accounts, followed by bulk extraction from cloud services. Source: BleepingComputer

This is a sector-specific warning from the healthcare industry’s own information-sharing body. Health-ISAC’s framing — “observed increase in successful attacks” — means the group is getting past defenses at a rising rate, not that it’s newly trying.

Why healthcare

Healthcare SSO is a high-value target for data theft. A single SSO account frequently controls access to EHR platforms, billing systems, patient portals, imaging archives, and cloud storage — all of it behind one set of credentials. ShinyHunters doesn’t need to compromise infrastructure; it needs one employee to hand over access under social pressure.

The sector’s structural vulnerabilities are well-documented: high turnover in patient-facing roles, 24/7 help desk operations, and identity verification disciplines that vary widely between facilities. Social engineering scales against those conditions.

The SSO playbook

ShinyHunters has used SSO and OAuth as consistent entry vectors across documented campaigns. Microsoft detailed three OAuth abuse paths the group ran against Salesforce-connected tenants in mid-July. Prior campaigns with a vishing component targeted Abbott, Exact Sciences, and LabCentral — those attribution claims remain disputed, but the pattern of targeting SSO at healthcare-adjacent organizations predates today’s advisory.

The group’s broader campaign has been active and escalating. EY data was compromised via a supply-chain attack on credentials. Stolen data has been weaponized in sextortion campaigns at $2,000 Bitcoin per target. Healthcare adds a specific downstream risk layer: patient records carry HIPAA liability, and OCR investigations compound the breach costs other sectors don’t face.

What to do

Four actions, ordered by impact on this specific attack pattern:

1. Harden help desk credential verification immediately. Out-of-band confirmation — callback to a known-good number, supervisor sign-off — for any credential reset or MFA bypass request. Social engineering exploits exception-handling, not policy gaps. The “urgent after-hours reset” is a common pretext; train for it specifically.

2. Audit SSO federation scope. Map which cloud services authenticate through your SSO provider and whether any retain a local credential fallback. If a service supports both federated and local auth and an attacker resets the local credential, SSO protections don’t apply.

3. Pull OAuth authorization logs for the past 30 days. New third-party application authorizations and bulk data export permissions are what you’re looking for. ShinyHunters lateral movement tends to appear as new OAuth grants before it shows up anywhere else.

4. Deploy phishing-resistant MFA on anything fronting cloud data. TOTP codes are socially engineerable — an attacker with a scripted real-time relay can beat them. Passkeys and hardware security keys remove that attack surface. Prioritize EHR and cloud storage access ahead of anything else.

The Health-ISAC advisory covers healthcare and medical technology organizations directly, but the SSO social engineering pattern is not sector-specific. Any organization with federated identity, a help desk that can initiate credential resets, and cloud-hosted data is in scope for this tradecraft.


Source: Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare — BleepingComputer, July 29, 2026.

Found this useful? Share it.