ShinyHunters has been more active. Google reports on the activity.
Google’s Threat Intelligence Group (GTIG) has been tracking the expansion of ShinyHunters-branded SaaS data theft. In a new blog post, they write: Mandiant has identified an expansion in threat activity that uses tactics, techniques, and procedures (TTPs) consistent with prior ShinyHunters-branded extortion operations. These operations primarily leverage sophisticated voice phishing (vishing) and victim-branded credential harvesting […]

SLSH Malicious “Supergroup” Targeting 100+ Organizations via Live Phishing Panels
Silent Push reports: A massive identity-theft campaign is currently active, targeting Okta Single Sign-On (SSO) and other SSO platform accounts across 100+ high-value enterprises. Silent Push has identified a surge in infrastructure deployment that mirrors the TTPs (Tactics, Techniques, and Procedures) of SLSH—a predatory alliance between Scattered Spider, LAPSUS$, and ShinyHunters. This isn’t a standard automated spray-and-pray attack; it is a […]