Back to Intel

Intel Node

Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft

highvulnerability2026-01-30T14:00:00+00:00source excerpt
vulnerabilitytradecraftdetectioncloudidentityemail

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Introduction Mandiant has identified an expansion in threat activity that uses tactics, techniques, and procedures (TTPs) consistent with prior ShinyHunters-branded extortion operations. These operations primarily leverage sophisticated voice phishing (vishing) and victim-branded credential harvesting sites to gain initial access to corporate environments by obtaining single sign-on (SSO) credentials and multi-factor authentication (MFA) codes. Once inside, the threat actors target cloud-based software-as-a-service (SaaS) applications to exfiltrate sensitive data and internal communications for use in subsequent extortion demands.

Google Threat Intelligence Group (GTIG) is currently tracking this activity under multiple threat clusters (UNC6661, UNC6671, and UNC6240 ) to enable a more granular understanding of evolving partnerships and account for potential impersonation activity.

Read Original Source