Skip to content
Breaking
Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech
SECURITY

Analysis: ShinyHunters claim hacks of Okta, Microsoft SSO accounts for data theft

ShinyHunters Extortion Gang Targets SSO Accounts in North East India and Beyond

ShinyHunters Extortion Gang Targets SSO Accounts in North East India and Beyond

In a series of ongoing voice phishing attacks, the ShinyHunters extortion gang has claimed responsibility for targeting single sign-on (SSO) accounts at Okta, Microsoft, and Google. The aim is to steal company data for extortion, posing a significant threat to businesses across the globe, including those in North East India.

Social Engineering Tactics

The attacks involve threat actors impersonating IT support, calling employees, and tricking them into entering their credentials and multi-factor authentication (MFA) codes on phishing sites that mimic company login portals. Once compromised, the attackers gain access to the victim's SSO account, potentially unlocking access to other connected enterprise applications and services.

North East India Connection

With numerous companies across North East India leveraging cloud services, the region is not immune to these attacks. The compromised SSO accounts can provide access to corporate systems and data, potentially leading to data breaches and financial losses.

Phishing Kits and Infrastructure

Okta has reported on the phishing kits used in these voice-based attacks, which allow attackers to dynamically change what a victim sees on a phishing site while speaking to them on the phone. This allows threat actors to guide victims through each step of the login and MFA authentication process.

ShinyHunters' Claims and Targets

ShinyHunters has confirmed its involvement in the attacks, stating that Salesforce remains its primary interest, while other SSO platforms, including Okta and Microsoft Entra, are benefactors. Microsoft and Google have not shared any information about the impact on their products, but Google stated it has no evidence of its products being abused in the campaign.

Data Leaks and Impact

ShinyHunters is using data stolen in previous breaches to identify and contact employees. Last night, the group relaunched its Tor data leak site, which currently lists breaches at SoundCloud, Betterment, and Crunchbase. These breaches could potentially affect businesses in North East India, as they may have employees or partners associated with these companies.

Protecting Your Business

As businesses become increasingly reliant on cloud services, it is essential to implement robust security measures to protect against such attacks. This includes educating employees about social engineering tactics, using strong authentication methods, and regularly monitoring for signs of unauthorized access.

Looking Forward

As the threat landscape evolves, it is crucial for businesses in North East India to stay vigilant and proactive in their cybersecurity efforts. By adopting best practices and staying informed about emerging threats, businesses can better protect their data and maintain their competitive edge.