Cybercrime constantly evolves, adopting increasingly sophisticated techniques to bypass corporate defenses. A recent case involves the hacker group known as ShinyHunters, which orchestrated a particularly insidious attack campaign targeting Okta authentication systems of several companies.
Starting January 22, 2026, ShinyHunters launched a series of “vishing” (voice phishing) attacks to steal Okta SSO (Single Sign-On) credentials from employees of companies primarily operating in the fintech, asset management, and financial consulting sectors. The attackers used deceptive phone calls to induce victims to provide their credentials, thus gaining access to critical systems such as cloud storage, CRM, and other business services protected through Okta. According to sources, potential victims would also include well-known platforms such as SoundCloud, Crunchbase, and Betterment, although the exact details of all affected companies have not been made public.
The severity of these attacks lies in the nature of the SSO system, which functions as a “master key” for multiple business services. When a malicious actor obtains these credentials, they can access numerous systems and sensitive data with a single set of credentials. In this specific case, ShinyHunters used this access to extract confidential data, which they then used as leverage for blackmail and extortion. The group even created a new leak site on the dark web to publish the stolen data, increasing pressure on the victims.
To protect against similar threats, companies should immediately implement multi-factor authentication on all Okta accounts, with preference for methods that cannot be easily intercepted or imitated. It is also essential to train employees on recognizing vishing attacks, emphasizing that legitimate IT departments never request complete credentials over the phone. Companies should also carefully monitor abnormal accesses and review security policies related to SSO systems.
- Key points to remember:
- Vishing attacks represent a growing threat as they exploit the human element, often the weakest link in the security chain.
- SSO systems offer convenience but, if compromised, can simultaneously expose numerous critical services.
- Continuous staff training and the implementation of robust multi-factor authentication are essential to mitigate these risks.
Sources:
https://www.bleepingcomputer.com/news/security/okta-sso-accounts-targeted-in-vishing-based-data-theft-attacks/
https://hackread.com/shinyhunters-leak-soundcloud-crunchbase-betterment-data/
https://databreaches.net/2026/01/23/shinyhunters-group-opens-new-dark-web-leak-site-claims-responsibility-for-okta-vishing-campaign/
Source: DataBreaches