In a recent advisory, Health-ISAC warned that the ShinyHunters cybercriminal group is intensifying its attacks on the healthcare sector.

 

What happened

According to Bleeping Computer, the Health Information Sharing and Analysis Center (Health-ISAC) has issued a warning to healthcare organizations and medical technology companies following an increase in successful cyberattacks linked to the ShinyHunters extortion group. According to the advisory, the threat actor is increasingly targeting cloud-based software-as-a-service (SaaS) environments, using identity-focused attacks to steal sensitive data rather than deploying ransomware.

 

Going deeper

Rather than exploiting software vulnerabilities or deploying ransomware immediately, ShinyHunters focuses on gaining access to an organization's cloud identity infrastructure. Once attackers control an employee's identity, they can move through multiple connected applications using legitimate credentials, making the intrusion more difficult to detect.

According to the advisory, ShinyHunters frequently relies on sophisticated social engineering techniques, particularly voice phishing (vishing). Attackers impersonate trusted personnel, such as IT help desk staff, and convince employees to reveal one-time multi-factor authentication (MFA) codes or approve fraudulent authentication requests. In some cases, they direct victims to fake single sign-on (SSO) portals designed to harvest usernames and passwords. After obtaining these credentials, the group can authenticate as legitimate users and access cloud services including Microsoft 365, Google Workspace, Salesforce, and other business applications.

The advisory notes that once initial access is established, ShinyHunters rapidly searches for sensitive information, downloads large volumes of data, and may create additional accounts or register new authentication methods to maintain persistence. Since these activities often occur through legitimate cloud services using valid credentials, they can blend in with normal user behavior and evade traditional security tools that primarily monitor malware or network-based attacks.

Health-ISAC also warned that the group's operations are data theft-first rather than ransomware-first. Instead of encrypting systems to disrupt operations, ShinyHunters steals sensitive information, such as protected health information (PHI), employee records, financial data, and intellectual property, and uses the threat of public disclosure to extort victims. This approach allows attackers to monetize breaches without deploying malware, while still creating significant financial, operational, and reputational risks for healthcare organizations.

 

What was said

In its July advisory, Health-ISAC stated that “health sector organizations are facing an observed increase in successful attacks by the threat actor, ShinyHunters.” Rather than relying on traditional ransomware, the organization said the group has shifted its focus to compromising user identities and cloud-based SaaS platforms to steal sensitive data. According to the advisory, ShinyHunters typically follows a repeatable attack chain using voice phishing (vishing) to trick employees or IT help desks into resetting credentials or enrolling new devices, taking over SSO accounts such as Microsoft Entra, Okta, or Google Workspace, moving into connected SaaS applications, and rapidly exfiltrating data for extortion.

Health-ISAC described the threat actor as “behaving less like a ‘traditional ransomware crew’ and more like an identity- and SaaS-access extortion operation.” The advisory noted that, in recent incidents, ShinyHunters “specifically claimed vishing of multiple employees led to compromise of a Microsoft Entra SSO account, followed by data theft from SaaS and internal platforms,” including Microsoft 365, SharePoint, and other enterprise services.

To help organizations defend against these attacks, Health-ISAC said the tactics used by ShinyHunters “are the key lessons for defenders based on these recent cyber incidents.” The organization urged healthcare and medical technology organizations to strengthen identity security by implementing phishing-resistant MFA, hardening single sign-on environments, verifying help desk requests before resetting credentials or enrolling devices, monitoring cloud applications for unusual activity, and improving employee awareness of voice phishing and other social engineering techniques.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

The bigger picture

ShinyHunters has been linked to breaches across multiple industries, but healthcare and medical technology organizations are becoming increasingly attractive targets because of the value of PHI, research data, and intellectual property. In recent years, the group has been associated with attacks against healthcare technology companies including AdaptHealth, Medtronic, and OneMedical, while also compromising organizations in finance, retail, aviation, and telecommunications through similar identity-focused techniques.

As healthcare organizations increasingly rely on cloud services and interconnected SaaS platforms, this warning is a reminder that securing identities and cloud access has become just as important as protecting endpoints and networks against traditional malware.

Read more: Who are the ShinyHunters?

 

FAQS

Why are healthcare organizations attractive targets?

Healthcare organizations store valuable PHI, financial records, employee data, and research information. These datasets can be used for extortion, identity theft, or sold on cybercriminal marketplaces.

 

What is a single sign-on (SSO) account?

A single sign-on (SSO) account allows users to access multiple applications with one set of login credentials. If an attacker compromises an SSO account, they may gain access to numerous connected cloud services.

 

What are signs of a voice phishing attack?

Common warning signs include unsolicited calls claiming to be from IT support, urgent requests to approve MFA prompts, pressure to reset passwords immediately, requests for verification codes, or instructions to enroll a new device.