Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks

Health sector organizations have been warned about an increase in successful attacks by the ShinyHunters threat group. In contrast to ransomware actors, ShinyHunters conducts supply chain and identity attacks, targeting cloud SaaS and storage platforms. The group is focused on cloud-scale data exfiltration, with initial access typically achieved by voice-based social engineering (vishing) to reset passwords, MFA, or enroll new devices, according to a recent Health-ISAC cybersecurity alert.

Once account access is gained, they log in to the organization’s Okta, Microsoft Entra, or Google SSO dashboard, which lists all applications the account holder has access to, such as Microsoft 365, Salesforce, Dropbox, Google Drive, and other third-party platforms.  Data is rapidly exfiltrated, and victims are advised about the data theft. ShinyHunters demands a ransom payment to prevent the stolen data from being leaked on the group’s dark web data leak site.

In recent months, ShinyHunters has conducted successful attacks on several healthcare and medtech companies, including the medical device manufacturers Medtronic and iRhythm, and OneMedical, DentaQuest, AdaptHealth, and Him & Hers. Health-ISAC explained that in a recent attack on a health sector organization, ShinyHunters claimed to have conducted vishing attacks on multiple employees, allowing a Microsoft Entra account to be compromised and a significant amount of company data to be exfiltrated from SaaS and internal platforms such as Microsoft 365 and SharePoint.

Health-ISAC has shared practical, high-impact recommendations for healthcare and medtech companies to improve defenses against these types of campaigns, the most important of which involves breaking the attack chain between the vishing call and the SSO account takeover. Helpdesk and IAM support workflows can be hardened by requiring out-of-band identity proofing for any password or MFA reset, or device reenrollment. Procedures should be implemented that require verification of the request by a callback to a previously verified number, and manager approval for any privileged user. It should not be possible to perform the password/MFA reset or device re-enrolment on the same inbound call.

To harden MFA security against reset abuse, phishing-resistant MFA (FIDO2/WebAuthn security keys or equivalent) should be implemented for admins and high-risk groups, and ideally for all users. SMS/voice MFA and weak fallback methods should be disabled or tightly restricted, and strict controls should be implemented for MFA factor registration.

Since the target is SSO, which provides the keys to the kingdom, Health-ISAC recommends classifying these systems as Tier 0 – the most critical company assets. As such, MFA and compliant devices should be required for accessing sensitive cloud services, legacy authentication should be blocked, administrative portals should be limited to managed devices, and geo-velocity/impossible travel checks implemented.

Extortion is only possible with data exfiltration, so it is vital to closely monitor logs for signs of account takeover and large-scale data access. Health-ISAC recommends centralizing Microsoft Entra sign-in logs, audit logs, and SaaS audit logs into an SIEM and configuring alerts for new device enrolments, MFA factor registration OAuth reset events, new OAuth apps or unusual consent grants, unusual bulk downloads, atypical API calls, and new forwarding rules and mailbox delegation changes.

Healthcare employees may be familiar with traditional phishing attacks, but less familiar with vishing. Vishing should be incorporated into security awareness training programs, and consider running vishing simulations on the workforce, especially on individuals with privileged accounts, helpdesk IT staff, new hires, and remote workers.

Health-ISAC recommends a 30- to 60-day time frame for implementing the recommendations, starting with phishing-resistant MFA for high-risk users, strengthening helpdesk reset procedures, and enforcing conditional access policies. In addition, tabletop exercises should be conducted for containing compromised cloud accounts (token/session revocation).

The post Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks appeared first on The HIPAA Journal.