Canva, Atlassian, Epic Games Among the 100+ Enterprises Targeted by ShinyHunters Group
## Cybersecurity Update: Identity-Theft Campaign Targeting Enterprises
Cybersecurity Update: Identity-Theft Campaign Targeting Enterprises
An identity-theft operation is currently targeting over 100 high-value organizations across various industries. This threat is posed by the SLSH group, a coalition employing tactics from Scattered Spider, LAPSUS$, and ShinyHunters.
This campaign employs human operators to target employees directly through phone calls while simultaneously using fake login pages resembling legitimate company systems. The objective is to acquire credentials and security tokens from services like Okta, which provide access to all applications within an organization.
The operation utilizes a tool known as a "live phishing panel," which enables real-time interception of login details and security codes, potentially bypassing multi-factor authentication.
Organizations identified as major targets include Canva, Atlassian, Epic Games, HubSpot, and numerous financial institutions, healthcare providers, and real estate companies.
An identity-theft operation is currently targeting over 100 high-value organizations across various industries.
According to Silentpush analysts, the attack is not random but a strategically planned targeting of enterprises with considerable digital assets. The attackers use voice phishing, where they impersonate IT staff to request password resets or access. Concurrently, they manipulate fake login pages to match what the victim sees, enhancing the deception.
The attack relies on human orchestration rather than automated malware. Once initial access is gained through vishing and credential theft, attackers utilize the compromised single sign-on session as a "skeleton key" for accessing interconnected applications within the targeted organization. They then proceed laterally, impersonating employees in systems like Slack or Teams to gain higher privileges.
The operation follows the LAPSUS$ methodology, advancing to data theft and extortion, where attackers download sensitive information and demand ransom under the threat of public exposure. In some instances, enterprise systems are encrypted to escalate pressure for payment.
Immediate Actions for Targeted Organizations
Entities identified as potential targets should consider this threat an emergency. It is recommended to alert all employees about ongoing vishing attempts and immediately audit single sign-on logs for any suspicious activities, such as unfamiliar device enrollments or login locations.
For more details on this threat, visit the Silentpush report .
Based on reporting by Cyber Security News.
