Skip to content
NetarxImpact Database
Vishing (Voice Phishing)UnknownConfirmedCampaign

ShinyHunters SSO vishing campaign hits 100+ organizations

100+ organizations across technology, finance, biotech, energy, healthcare, logistics, retail and insurance · Other · Global · January 2026

What happened

Through January 2026 researchers at Okta, Mandiant, Sophos and Silent Push tracked an ongoing campaign in which callers impersonating IT support walked employees into fake single sign-on portals. More than 100 organisations were targeted and roughly 150 malicious lookalike domains were registered. Silent Push named Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos and Telstra among those targeted; Betterment, Crunchbase and SoundCloud were confirmed breached.

How the deception worked

Operators phoned employees claiming to be internal IT or a trusted service provider, then drove them to a domain mimicking their Okta, Microsoft Entra or Google sign-in page. The phishing kits carried client-side scripts that let the attacker steer the victim's browser in real time, so the caller's spoken instructions stayed in step with what the employee saw on screen. That synchronisation let them prompt for the exact MFA code or push approval at the right moment, harvesting credentials and live session tokens, then pivoting into connected SaaS tenants to bulk-export data for extortion.

The control that would have caught it· our reading, not a claim from the sources

Phishing-resistant MFA bound to the origin (FIDO2 passkeys, device-bound certificates) removes the code the caller is trying to talk out of the employee; conditional access limiting sign-in to managed devices closes the rest.

Sources (2)

  1. Over 100 Organizations Targeted in ShinyHunters Phishing Campaign
    SecurityWeek·securityweek.comOpen ↗
  2. A new wave of 'vishing' attacks is breaking into SSO accounts in real time
    CyberScoop·cyberscoop.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.