Cybersecurity researchers are sounding the alarm about a new, active campaign attributed to the ShinyHunters cybercrime collective that uses sophisticated voice-phishing (vishing) techniques to compromise single sign-on (SSO) credentials and infiltrate enterprise SaaS environments.
According to Google and Mandiant, the group is employing “evolved vishing techniques to successfully compromise SSO credentials from victim organisations, and enrol threat actor controlled devices into victim MFA solutions. This is an active and ongoing campaign. After gaining initial access, these actors pivot into SaaS environments to exfiltrate sensitive data. An actor that identifies as ShinyHunters has approached some of the victim organisations with an extortion demand.” — Charles Carmakal, CTO, Mandiant Consulting.
Real-Time Social Engineering Meets Phishing Kits
Recent industry tracking shows that threat actors are combining voice calls with real-time phishing kits, guiding victims through fake login flows for Okta, Google Workspace, Microsoft 365 and other identity providers. Attackers typically pose as internal IT or helpdesk staff to build trust before capturing credentials and multifactor authentication (MFA) approvals.
Okta threat intelligence alerts describe these phishing kits as capable of relaying credentials and bypassing push-based MFA by guiding victims in real time — a marked evolution from traditional email phishing attacks.
Wider Targeting, Major Tech Firms in Scope
Security researchers also report that ShinyHunters’ latest campaign has targeted over 100 organisations, with malicious domains set up to target SSO systems at companies including Atlassian, Canva, HubSpot, ZoomInfo and Telstra. While not all targeted organisations have confirmed breaches, the scale indicates broad reconnaissance and targeting.
Why Vishing Works — and How to Mitigate
Unlike technical exploits, these attacks exploit human trust and the limitations of traditional MFA. Security advocates are now pushing enterprises to adopt phishing-resistant MFA methods, such as FIDO2 security keys or passkeys, which cryptographically bind authentication to legitimate domains and cannot be relayed by attackers — a step explicitly recommended by Mandiant in its advisory.
Organisations are advised to monitor for anomalous API activity, enforce strict app authorisation policies, and implement continuous log monitoring to detect unauthorised device enrolments or suspicious login patterns early.
The Evolving Threat Landscape
While the campaign’s success varies, the blend of voice phishing with dynamic credential theft represents a significant evolution in social engineering attacks — one that traditional security stacks struggle to detect. As the techniques mature, defenders must shift focus from solely technical controls to include user awareness, credential hygiene, and modern authentication frameworks.








