‘The variety of specific cloud platforms continues to expand’: Google security team discusses how ShinyHunters has implemented so many SSO scams recently



  • ShinyHunters uses vishing and custom phishing pages to bypass SSO protections
  • Stolen MFA codes grant access to platforms like Salesforce, Microsoft 365, and Dropbox
  • Other groups imitate tactics; Experts urge phishing-resistant MFA and Zero Trust defenses

A highly effective combination of vishing (voice phishing) and custom infrastructure has allowed the feared extortion gang ShinyHunters to launch countless single sign-on (SSO) scams in recent times, experts concluded.

A new report from Google’s Mandiant experts has explained the modus operandi behind a wave of SSO attacks that hit businesses across industries recently, saying it all starts with a phone call.



Leave a Comment

Your email address will not be published. Required fields are marked *