A ShinyHunters-branded voice phishing campaign is using real-time phishing kits to steal Okta SSO credentials, bypass MFA, and pivot into SaaS for data theft and extortion.
A ShinyHunters-branded cybercrime operation is pushing voice phishing into a new tier of effectiveness by pairing phone-based social engineering with “live” phishing kits that can manipulate what a victim sees in their browser in real time. The result is straightforward: stolen single sign-on credentials, coerced MFA approvals, and rapid pivoting into SaaS environments for data theft and extortion.
This is not a story about a software flaw in a vendor platform. It is a story about attackers operationalizing human-in-the-loop tradecraft against the identity layer, which remains the highest-leverage control plane in modern enterprises.
What happened
According to reporting from Cybersecurity Dive, the cybercrime group ShinyHunters claimed credit for at least five attacks tied to a voice phishing campaign previously disclosed by Okta.
Okta’s threat intelligence team described custom phishing kits designed specifically for callers who keep targets on the phone while controlling the authentication flow in the target’s browser. These kits can intercept credentials and help attackers pressure users into actions that defeat MFA controls that are not phishing-resistant.
Multiple security and threat intelligence teams have been tracking the infrastructure behind the campaign, including a cluster of roughly 150 domains created in December and themed to mimic SSO services and authentication providers.
Mandiant assessed the campaign as active and ongoing, describing successful compromise of SSO credentials and enrollment of attacker-controlled devices into victim MFA solutions, followed by pivoting into SaaS environments for data theft and extortion demands.
Why this campaign is different
Classic phishing relies on static fake login pages and user inattention. This wave uses real-time orchestration.
Okta’s analysis explains the typical sequence:
Reconnaissance on the target, including user names, commonly used apps, and phone numbers used in support calls
Phone spoofing to impersonate IT or a help desk hotline
A customized phishing site brought online for that specific target
Credentials captured and forwarded instantly to the attacker
The phishing page updated live to match whatever MFA challenge the real sign-in prompts, synchronized with the caller’s instructions
The practical impact is that MFA methods that are not phishing-resistant can be socially engineered in real time, including push approvals and one-time passcodes. Okta also notes that number-matching push prompts are not inherently phishing-resistant when a caller can simply instruct the user which number to choose.
This is the core lesson: identity defenses that assume the user will detect “something off” are losing to kits engineered to make the experience feel consistent, guided, and legitimate.
Why Okta SSO is a high-value target
SSO is a force multiplier for defenders and attackers. When one identity becomes a gateway to many apps, the payoff for compromising it rises sharply. Reporting around the campaign emphasizes that attackers are targeting SSO credentials to reach downstream services, steal sensitive data, and then monetize access through extortion.
From an enterprise risk standpoint, this shifts breach likelihood toward the “front door” of SaaS: identity, device enrollment, session controls, and administrative policy.
Defensive priorities that actually reduce vishing risk
The common failure mode is over-investing in awareness training while under-investing in controls that remove the attacker’s ability to succeed even with a cooperative user.
1) Move to phishing-resistant MFA for high-impact access paths
Mandiant explicitly recommends phishing-resistant MFA such as FIDO2 security keys or passkeys.
This matters because the attacker’s advantage comes from harvesting secrets that can be replayed or socially coerced.
2) Lock down MFA device enrollment and abnormal enrollment patterns
Mandiant highlighted attacker-controlled device enrollment into victim MFA solutions as part of the campaign pattern. Detection and prevention controls need to focus here: enrollment approvals, enrollment velocity anomalies, enrollment from unusual networks, and enrollment tied to new sessions.
3) Treat help desk and support processes as a hardened control point
These campaigns exploit the legitimacy of “support.” Hardening is operational, not just technical:
strict identity verification workflows for account recovery and resets
out-of-band validation for high-privilege users
enforced call-back policies to known numbers for sensitive actions
reduced discretion in exceptions, supported by written playbooks
Okta’s sequence description makes clear that attackers are building the pretext and infrastructure around trusted support channels.
4) Monitor for the artifacts these kits create
Mandiant recommends monitoring logs for unusual API activity and unauthorized device enrollments, and enabling stronger authorization “strike” policies for app authorization.
In parallel, domain intelligence and brand monitoring can surface the target-specific lookalike domains that underpin the live phishing experience.
5) Reduce blast radius inside SaaS after initial access
Mandiant described post-compromise pivoting into SaaS environments and data exfiltration.
Controls that slow and expose this phase include conditional access, least privilege in SaaS admin roles, session risk policies, alerting on bulk export behaviors, and tighter governance of OAuth and third-party app authorizations.
InfoSight perspective: identity belongs inside continuous exposure management
This campaign is a clean example of why “security posture” cannot be measured only in patch status and endpoint coverage. Exposure lives in workflows and control points attackers can manipulate, especially identity operations.
A practical way to operationalize this is to treat identity controls as continuously testable and continuously improvable:
validate MFA posture by application tier and privilege tier
test and harden help desk and account recovery procedures as an attack surface
instrument identity telemetry so device enrollment and session anomalies create immediate investigation paths
enforce remediation accountability with evidence, not intent
In InfoSight engagements, this maps cleanly to an outcomes-driven approach: identify the control gaps that enable real intrusion paths, prioritize fixes that remove attacker leverage, and verify that changes measurably reduce the window of exposure across identity and SaaS access.
Key takeaways
ShinyHunters is claiming credit for a vishing campaign tied to custom phishing kits disclosed by Okta.
These kits synchronize a phone call with live browser manipulation, enabling MFA defeat for methods that are not phishing-resistant.
Threat intelligence teams observed active infrastructure including large clusters of themed domains used to support the attacks.
Mandiant describes ongoing compromise of SSO credentials, attacker-controlled MFA enrollment, SaaS pivoting, and extortion attempts, and recommends phishing-resistant MFA and enhanced monitoring.
Subscribe to our newsletter to keep you updated on the latest cybersecurity insights & resources.
One follow-up from a security expert—no spam, ever.
Enter your details below to download the PDF.