Voice-phishing campaign targets single sign-on accounts in real time

THE BRIEF
CyberScoop reports a new wave of voice-phishing attacks targeting single sign-on tools, with threat hunters and researchers working to contain activity that has led to reported data theft and extortion attempts. The attacks reportedly combine phone calls with advanced phishing kits to persuade victims to surrender access. One group identifying itself as ShinyHunters has publicly named alleged targets and posted samples of purportedly stolen data. The reported activity shares characteristics with earlier campaigns attributed to ShinyHunters, including the abuse of third-party vendors to gain initial access to multiple company networks. CyberScoop also cites Mandiant as tracking an ongoing, ShinyHunters-branded campaign using evolved voice-phishing techniques to compromise SSO credentials from victim organizations. The report links the broader group’s previous activity to an attack spree that affected more than 700 Salesforce customer environments last fall. The supplied report does not establish the full scope or independently verify every claim.
WHY IT MATTERS
Single sign-on credentials can provide a direct route into an organization’s identity environment, making real-time social engineering a serious concern even where phishing-resistant controls are being considered. The reported combination of phone calls, phishing kits and third-party access illustrates how attackers may target both employees and trusted vendors. Public claims and posted samples can increase pressure on organizations while investigations continue. Security teams should treat the reporting as a warning to review identity protections, vendor access and procedures for handling unusual authentication requests, without assuming that every alleged target or impact has been confirmed.
WHO SHOULD CARE
Identity and security leaders, help desks, fraud teams, procurement and third-party risk managers, and administrators responsible for SSO, authentication enrollment and vendor access should review their exposure to voice-phishing tactics.
WHAT TO DO NOW
- Require independent verification through a known channel before approving unusual SSO, MFA or authentication-enrollment requests made by phone.
- Review SSO logs and identity-provider alerts for suspicious sign-ins, credential changes, authentication-enrollment activity and unusual access patterns.
- Reassess third-party vendor access, limiting permissions and reviewing recent authentication or account changes associated with external users.