← SaaS News
SaaS

Mandiant Flags ShinyHunters‑Style Vishing Attacks Bypassing MFA on SaaS Platforms

Mandiant Flags ShinyHunters‑Style Vishing Attacks Bypassing MFA on SaaS Platforms

Cybersecurity firm Mandiant has identified an active vishing campaign tied to the ShinyHunters criminal syndicate that harvests MFA codes to infiltrate SaaS platforms. The operation, tracked under UNC6661, UNC6671 and UNC6240, demonstrates that social engineering can defeat multi‑factor authentication without exploiting software flaws.

The campaign illustrates that even the most widely deployed security controls—SSO and MFA—can be subverted through human manipulation, eroding confidence in current identity‑centric defenses. For SaaS operators, the breach vector threatens the core trust model that underpins subscription revenue, as compromised accounts can lead to data loss, regulatory penalties and reputational damage. The incident accelerates the market push toward phishing‑resistant, passwordless authentication and reinforces the strategic importance of zero‑trust frameworks in SaaS product design.

For investors and founders, the rise of credential‑relay attacks signals a new risk factor that could affect valuation models, especially for companies whose go‑to‑market relies on self‑service sign‑ups and low‑friction onboarding. Vendors that can demonstrate robust, built‑in defenses against social engineering will likely command premium pricing and enjoy stronger customer retention, while those lagging may face churn and heightened compliance scrutiny.

  1. Mandiant identifies a vishing campaign linked to ShinyHunters that harvests MFA codes in real time.
  2. Attackers impersonate IT staff, guide victims to counterfeit SSO portals, and relay credentials instantly.
  3. The operation targets any SaaS platform using SSO‑driven MFA, regardless of product version.
  4. Phishing‑resistant MFA methods (FIDO2, biometrics) and zero‑trust controls are recommended mitigations.
  5. NCC‑CSIRT urges device registration, anomalous login monitoring, and regular vishing awareness training.

The ShinyHunters‑style vishing campaign marks a pivotal shift from code‑centric exploits to pure social engineering at scale. Historically, SaaS breaches have often hinged on software bugs, misconfigurations, or credential stuffing. This new vector sidesteps those defenses entirely, exploiting the trust relationship between employees and internal support teams. The rapid credential relay technique is reminiscent of early man‑in‑the‑middle attacks, but its integration with live voice phishing makes it uniquely effective against modern MFA deployments.

From a market perspective, the incident could catalyze a wave of product differentiation around identity security. SaaS vendors that embed hardware‑based MFA or offer integrated zero‑trust access controls may capture a larger share of security‑budget allocations, especially among regulated verticals like finance and healthcare. Conversely, platforms that continue to rely on SMS or app‑generated codes risk becoming legacy liabilities, prompting customers to demand stronger authentication guarantees as a condition of renewal.

Looking ahead, threat actors are likely to augment vishing with deep‑fake audio and AI‑generated caller IDs, raising the bar for social‑engineering defenses. Enterprises will need to invest not only in technology but also in continuous, scenario‑based training that mirrors these evolving tactics. The broader SaaS ecosystem must treat identity hygiene as a product feature rather than an afterthought, integrating phishing‑resistant mechanisms into the core user experience to preserve the trust that fuels subscription growth.

ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platformscsirt.ncc.gov.ngShinyHunters Claims Credit for Voice Phishing Attacks Targeting Okta SSOinfosightinc.comShinyHunters at Scale: A Case Study in AI-Assisted Cybercrimecyera.comHealthcare Sector Faces Surge in Vishing and Phishing Attacks, Researchers Warn - CRBC Newscrbcnews.comHow Did ShinyHunters Breach McKesson’s Healthcare Data? | Biopharma Curatedbiopharmacurated.comTelus Digital Cyberattack: What the ShinyHunters Breach Reveals About Modern Cyber Riskinfosightinc.comShinyHunters Hackers Renew Attacks on Oracle PeopleSoft Flaw, Google's Mandiant Reports · TrustFinance Newsnews.trustfinance.comMandiant Reports ShinyHunters Renews Global PeopleSoft Attacks — IJR Newsijr.comShinyHunters Resume Oracle PeopleSoft Attacks After Bypassing Defenses | Ukraine news - #Mezhamezha.netShinyHunters Hackers Renew Mass Exploitation of Oracle PeopleSoft Software - Memesitamemesita.com