Healthcare cybersecurity group warns of vishing, domain impersonation

Advertisement

Health-ISAC has issued a threat bulletin warning that the ShinyHunters cybercrime group is running targeted voice phishing (aka vishing) campaigns and registering medical-themed impersonation domains to breach health sector organizations.

The nonprofit cybersecurity information-sharing group said Sept. 3 it has sent targeted alerts to multiple health sector organizations over the past two weeks after observing ShinyHunters bypass multifactor authentication to pivot from single sign-on platforms into connected SaaS applications, including Microsoft 365, SharePoint and Salesforce, for large-scale data exfiltration and extortion.

The attackers register lookalike domains using a target company’s name paired with “-claims[.]com” or similar endings, then call and leave voicemails for employees on personal mobile devices while impersonating internal departments such IT help desks, according to Health-ISAC. Victims who enter credentials on the spoofed pages have that information relayed in real time to the legitimate login portal through reverse-proxy phishing kits, and are then pressured by phone to approve an MFA prompt.

Health-ISAC recommended organizations block the .claim and .claims top-level domains, move to phishing-resistant MFA such as FIDO2 or passkeys, require strict verification for helpdesk MFA resets, and restrict SaaS access to corporate-managed devices.

The bulletin follows Health-ISAC’s earlier warning tying ShinyHunters to a data-theft campaign that included the alleged breach of Baxter International, underscoring the group’s shift toward identity- and SaaS-access extortion across the health sector.

Advertisement

Next Up in Cybersecurity

Advertisement