Topic: vishing attacks

  • How ShinyHunters Hackers Exploit SSO to Steal Cloud Data

    How ShinyHunters Hackers Exploit SSO to Steal Cloud Data

    The ShinyHunters group uses sophisticated voice phishing (vishing) to steal employee credentials and bypass multi-factor authentication by impersonating IT support and using fake login pages. Once inside via a compromised single sign-on (SSO) account, attackers gain a centralized springboard to a...

    Read More »
  • Okta Users Targeted by Advanced Phishing & Vishing Kits

    Okta Users Targeted by Advanced Phishing & Vishing Kits

    New phishing kits enable real-time credential interception and control of authentication flows, targeting users of major identity platforms like Google and Microsoft. These attacks combine voice phishing with dynamic, convincing fake login pages that bypass multi-factor authentication methods lik...

    Read More »
  • BlackFile Group Targets Retail, Hospitality via Vishing Attacks

    BlackFile Group Targets Retail, Hospitality via Vishing Attacks

    A new cyber extortion group, CL-CRI-1116, linked to BlackFile and "The Com," has targeted retail and hospitality sectors since February 2026, using vishing attacks and living-off-the-land strategies to steal credentials and bypass MFA. The group abuses APIs and SharePoint to exfiltrate sensitive ...

    Read More »
  • Okta SSO accounts targeted in vishing data theft attacks

    Okta SSO accounts targeted in vishing data theft attacks

    A new wave of sophisticated phishing attacks uses real-time voice calls and adversary-in-the-middle platforms to steal employee Okta credentials and bypass multi-factor authentication (MFA) by manipulating victims during live conversations. Attackers conduct detailed reconnaissance, spoof interna...

    Read More »
  • Microsoft Entra Accounts Targeted in Vishing Attacks

    Microsoft Entra Accounts Targeted in Vishing Attacks

    A new wave of attacks combines device code phishing with voice phishing (vishing) to compromise Microsoft Entra accounts, exploiting the legitimate OAuth 2.0 device authorization flow to steal authentication tokens without traditional password theft. The **ShinyHunters** extortion group is believ...

    Read More »
  • ShinyHunters' New MFA Bypass Fuels Data Theft

    ShinyHunters' New MFA Bypass Fuels Data Theft

    A sophisticated social engineering campaign is bypassing multi-factor authentication (MFA) using synchronized voice and email phishing attacks, successfully targeting major companies like Panera Bread and Match Group. Attackers, linked to groups like UNC6661 and ShinyHunters, use IT impersonation...

    Read More »
  • Protect Your Business from Deepfakes: 4 Essential Steps Now

    Protect Your Business from Deepfakes: 4 Essential Steps Now

    Deepfakes, created using AI, are a growing threat to businesses, enabling cybercriminals to produce convincing fake audio and video for fraud and misinformation. The risks include severe reputational and financial damage, such as stock value drops from fake announcements, and identity theft throu...

    Read More »
  • Amgen cloud breach exposes patient health, proprietary data

    Amgen cloud breach exposes patient health, proprietary data

    Amgen confirmed a data breach in July 2026 involving theft of corporate files and patient health information from third-party cloud environments, prompting activation of its cybersecurity response and forensic investigation. Stolen data includes proprietary company information and patient protect...

    Read More »
  • Telus Digital Confirms Major Data Breach After Hacker Claims

    Telus Digital Confirms Major Data Breach After Hacker Claims

    Telus Digital, a Canadian telecom BPO, confirmed a major data breach by the ShinyHunters group, who allegedly stole nearly a petabyte of sensitive client and consumer data over several months. The attackers reportedly used credentials from a prior breach at Salesloft Drift to access Telus systems...

    Read More »
  • Odido Data Breach: ShinyHunters Gang Claims Millions Affected

    Odido Data Breach: ShinyHunters Gang Claims Millions Affected

    The ShinyHunters extortion gang breached Dutch telecom provider Odido, potentially exposing millions of customers' sensitive personal data like names, addresses, and ID numbers, though the company states passwords and financial details were not compromised. Odido and the attackers dispute the sca...

    Read More »
  • Google Denies Gmail Scam Risk – But You Still Need to Do This

    Google Denies Gmail Scam Risk – But You Still Need to Do This

    Google denies recent claims of increased scam risks for Gmail users on desktops and laptops, asserting that its security systems are strong and block over 99.9% of threats. Users are advised to enhance account security by regularly updating passwords and enabling two-factor authentication, while ...

    Read More »