Health-ISAC is warning healthcare and medtech organizations about a rise in successful ShinyHunters attacks that use vishing, phishing, and supply chain compromise to take over SSO accounts and steal cloud data. The group has targeted platforms such as Microsoft Entra, Salesforce, Microsoft 365, and SharePoint, with recent activity linked to organizations including Medtronic, DentaQuest, iRhythm, and OneMedical. #ShinyHunters #HealthISAC #MicrosoftEntra #Salesforce #Microsoft365 #SharePoint #Medtronic #DentaQuest #iRhythm #OneMedical
Keypoints
- ShinyHunters is increasing attacks against healthcare and medtech organizations.
- The group uses vishing and phishing to reset passwords and take over SSO accounts.
- Compromised SSO access lets attackers reach many connected SaaS applications and steal data.
- Health-ISAC advises stronger helpdesk verification and phishing-resistant MFA for high-risk users.
- Organizations should monitor logs for suspicious MFA changes, OAuth grants, and bulk data downloads.