‘The breadth of targeted cloud platforms continues to expand’: Google’s security team takes a look at how ShinyHunters have been rolling out so many SSO scams recently


  • ShinyHunters uses vishing and custom phishing pages to bypass SSO protection
  • Stolen MFA codes provide access to platforms such as Salesforce, Microsoft 365 and Dropbox
  • Other groups mimic tactics; experts call for phishing-resistant MFA and Zero Trust defenses

A highly effective combination of vishing (voice phishing) and customized infrastructure has enabled the dreaded ShinyHunter extortion gang to launch countless single sign-on (SSO) scams in recent times, experts have concluded.

A new report from Google’s Mandiant experts has explained the modus operandi behind a wave of SSO attacks hitting businesses across industries recently, saying it all starts with a phone call.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top