ShinyHunters Extortion Gang Targets SSO Accounts in North East India and Beyond
In a series of ongoing voice phishing attacks, the ShinyHunters extortion gang has claimed responsibility for targeting single sign-on (SSO) accounts at Okta, Microsoft, and Google. The aim is to steal company data for extortion, posing a significant threat to businesses across the globe, including those in North East India.
Social Engineering Tactics
The attacks involve threat actors impersonating IT support, calling employees, and tricking them into entering their credentials and multi-factor authentication (MFA) codes on phishing sites that mimic company login portals. Once compromised, the attackers gain access to the victim's SSO account, potentially unlocking access to other connected enterprise applications and services.
North East India Connection
With numerous companies across North East India leveraging cloud services, the region is not immune to these attacks. The compromised SSO accounts can provide access to corporate systems and data, potentially leading to data breaches and financial losses.
Phishing Kits and Infrastructure
Okta has reported on the phishing kits used in these voice-based attacks, which allow attackers to dynamically change what a victim sees on a phishing site while speaking to them on the phone. This allows threat actors to guide victims through each step of the login and MFA authentication process.
ShinyHunters' Claims and Targets
ShinyHunters has confirmed its involvement in the attacks, stating that Salesforce remains its primary interest, while other SSO platforms, including Okta and Microsoft Entra, are benefactors. Microsoft and Google have not shared any information about the impact on their products, but Google stated it has no evidence of its products being abused in the campaign.
Data Leaks and Impact
ShinyHunters is using data stolen in previous breaches to identify and contact employees. Last night, the group relaunched its Tor data leak site, which currently lists breaches at SoundCloud, Betterment, and Crunchbase. These breaches could potentially affect businesses in North East India, as they may have employees or partners associated with these companies.
Protecting Your Business
As businesses become increasingly reliant on cloud services, it is essential to implement robust security measures to protect against such attacks. This includes educating employees about social engineering tactics, using strong authentication methods, and regularly monitoring for signs of unauthorized access.
Looking Forward
As the threat landscape evolves, it is crucial for businesses in North East India to stay vigilant and proactive in their cybersecurity efforts. By adopting best practices and staying informed about emerging threats, businesses can better protect their data and maintain their competitive edge.