Cybersecurity Alert: ShinyHunters Strikes with Sophisticated Voice Attacks

At the beginning of 2026, the cybersecurity landscape was shaken by a particularly insidious attack campaign. The hacker group known as ShinyHunters (also identified as UNC6661, UNC6671, UNC6240) launched a series of targeted attacks combining social engineering techniques and advanced technology to hit over 100 organizations across various sectors.

Since January 2026, ShinyHunters has orchestrated a sophisticated “vishing” (voice phishing) campaign in which criminals call victims pretending to be technical support staff. During these calls, they convince victims to enter their credentials on fake authentication sites that perfectly mimic legitimate services like Okta, Google, and Microsoft. This allows them to bypass two-factor authentication (MFA) systems, register their devices as trusted, and access numerous business applications such as SharePoint, OneDrive, and Salesforce. Once inside, they steal sensitive data and often demand ransom payments by threatening to publish the stolen information.

The impact of this campaign has been devastating. Among the most notable victims is SoundCloud, with data from 36 million users compromised. Companies such as Betterment, Qantas, Allianz Life, LVMH/Chanel, Workday, and even Google’s corporate Salesforce instance have been affected. The most targeted sectors include finance, education, energy, retail, real estate, and cryptocurrencies. In addition to data theft, victims have faced extortion demands, staff harassment, and, in some cases, the publication of stolen data.

To protect against these attacks, organizations should implement more rigorous verification protocols for technical support requests, train staff to recognize vishing attempts, and implement more robust authentication systems that don’t rely solely on temporary codes. Users should be wary of any unexpected calls requesting personal information or asking them to access certain websites, even if they seem to come from trusted sources.

  • Key points to remember:
  • Vishing attacks are on the rise and becoming increasingly sophisticated, combining social engineering and advanced technology
  • Even multi-factor authentication systems can be compromised if users are manipulated into entering their credentials on fraudulent sites
  • Staff training and clear verification protocols are essential to mitigate these risks

Sources:
https://thehackernews.com/2026/01/mandiant-finds-shinyhunters-using.html
https://nationalcioreview.com/articles-insights/extra-bytes/shinyhunters-exploit-sso-weaknesses-in-real-time-vishing-attacks/
https://www.computerweekly.com/news/366637762/Wave-of-ShinyHunters-vishing-attacks-spreading-fast
https://www.cybersecuritydive.com/news/cybercrime-group-voice-phishing-attacks-Okta/810493/

Source: Mandiant