Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
AI Generated Image

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

BleepingComputer technology

Key Points:

  • Health-ISAC warns of increased successful attacks by the extortion group ShinyHunters targeting healthcare and medical technology organizations through supply chain and identity attacks on cloud SaaS platforms.
  • ShinyHunters use social engineering tactics, including vishing and phishing, to compromise corporate single-sign-on (SSO) accounts, gaining access to multiple SaaS applications like Salesforce, Microsoft 365, and Google Drive from a single compromised account.
  • The attack chain typically begins with voice phishing to manipulate employees or helpdesk staff into resetting passwords or MFA settings, enabling attackers to rapidly steal data for extortion purposes.
  • Health-ISAC advises implementing out-of-band identity verification for password and MFA resets, enforcing strict helpdesk policies, deploying phishing-resistant MFA (such as FIDO2 security keys), and treating SSO systems as critical assets with enhanced access controls.
  • Organizations should centralize audit logs, monitor for suspicious activities, restrict API tokens and third-party integrations, and prioritize incident response capabilities to quickly contain compromised cloud accounts.

Trending Business

Trending Technology

Trending Health