BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ShinyHunters Expand Saas Attacks with Vishing Campaign

Surging voice phishing attacks steal credentials to hijack SaaS data for extortion.

  • Google’s Mandiant reported a surge in advanced voice phishing attacks by the ShinyHunters group, targeting SaaS applications for data theft and extortion on January 31, 2026.
  • The hackers impersonate IT staff to steal single sign-on credentials and MFA codes, subsequently accessing and exfiltrating sensitive corporate data from platforms like SharePoint and OneDrive.
  • Cryptocurrency-focused companies are among the targets, with actors using compromised email accounts to launch further phishing campaigns and then deleting the evidence.
  • Google recommends moving to phishing-resistant MFA like FIDO2 security keys and improving help desk verification processes, as detailed in its hardening guide.

On January 31, 2026, Google‘s threat intelligence arm Mandiant identified a dangerous expansion in financially motivated cyberattacks, according to a new report. The activity, linked to the ShinyHunters extortion group, uses sophisticated voice phishing to steal employee credentials and hijack cloud-based applications.

- Advertisement -

Attackers, tracked as UNC6661 and UNC6671, pose as IT support staff in phone calls directing victims to fake login pages. Once they obtain multi-factor authentication codes, they register their own devices and move laterally across corporate networks.

Consequently, the hackers siphon sensitive data from software-as-a-service platforms to extort the victims. In some cases, they even weaponize access to compromised email accounts for additional phishing, specifically targeting cryptocurrency firms.

Meanwhile, Google has outlined extensive defensive measures to counter this rising threat to SaaS security. Recommendations include enforcing device access controls and monitoring for suspicious OAuth authorization events with tools like ToogleBox Email Recall.

“This activity is not the result of a security vulnerability in vendors’ products or infrastructure,” Google stated. The company stressed that the attacks highlight the critical need for organizations to adopt phishing-resistant authentication methods.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SHIB Crashes to 2021 Price Levels, Sparking Investor Worry

Shiba Inu (SHIB) has fallen below $0.000005, a price level last seen in May...

Zcash Rallies 19% After Bug Fix; Founder: No Funds Stolen

ZCash (ZEC) surged 19% on June 6, sharply outperforming Bitcoin (BTC) after a major...

Smart TVs Co-opted Into AI Data-Scraping Network

A security researcher has reverse-engineered how a popular data firm turns consumer devices, including...

Ether Hits 13-Month Low Amid DeFi Liquidations, Bug

Ether derivatives metrics turned heavily bearish after cascading liquidations prevented a recovery.A critical ZCash...

Zcash Plunges After Critical Four-Year-Old Bug Revealed

ZCash's price dropped sharply after disclosure of a critical, four-year-old vulnerability.The bug's full scope...

Must Read

Top 5 Best Crypto Faucets To Earn Free Crypto This Year

QUICK LINKSWhat Are Crypto Faucets and How Do They Work?How Do Crypto Faucets Make Money?What to Expect: Realistic EarningsThe Best Crypto Faucets of 2025:...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading