Quick Summary
The Securityish Brief
Mandiant, a cybersecurity firm owned by Google, reported on January 31, 2026, an increase in vishing attacks that utilize tactics similar to those of the ShinyHunters hacking group. These attacks involve advanced voice phishing and fake credential harvesting sites designed to collect single sign-on (SSO) credentials and MFA codes from employees of targeted organizations. The attackers aim to infiltrate cloud-based SaaS applications to steal sensitive data and internal communications.
The threat intelligence team at Mandiant is monitoring this activity under clusters such as UNC6661, UNC6671, and UNC6240, indicating that these groups may be evolving their methods or mimicking past tactics. The attacks have been observed primarily in January 2026, with specific instances of impersonation of IT staff to deceive employees into providing their credentials.
For example, UNC6661 has been noted for directing victims to credential harvesting links while posing as IT personnel, while UNC6671 has been identified as using similar tactics to gain access to Okta customer accounts. The stolen credentials are then used to register devices for MFA, allowing attackers to move laterally within networks and exfiltrate data from SaaS platforms.
The differences in domain registration methods between UNC6661 and UNC6671 highlight the complex nature of these cybercrime groups, suggesting that various individuals may be involved. The targeting of cryptocurrency firms indicates a potential for further financial exploitation by these attackers.
Implications for Organizations
Organizations must recognize the increasing sophistication of social engineering tactics used in these vishing attacks. The incidents underscore the importance of implementing phishing-resistant MFA solutions, such as FIDO2 security keys, which are less vulnerable to social engineering than traditional SMS or email-based methods.
To mitigate risks, companies should enhance their help desk processes, requiring identity verification through live video calls. Additionally, limiting access to trusted egress points and enforcing strong password policies can help protect sensitive information.
Implementing comprehensive logging practices will increase visibility into identity actions and SaaS export behaviors, while monitoring for unusual MFA device enrollment activities can help detect potential breaches early. Organizations are encouraged to audit their security measures regularly to adapt to evolving threats.
Key Takeaways
- Implement phishing-resistant MFA solutions, such as FIDO2 security keys, to enhance security against social engineering attacks.
- Enhance help desk processes by requiring live video calls for identity verification before assisting users.
- Limit access to trusted egress points and enforce strong password policies to safeguard sensitive data.
- Regularly audit security measures and implement logging to monitor identity actions and SaaS export behaviors.
- Monitor for unusual MFA device enrollment activities to detect potential breaches early.
Key Terms & Concepts
- Vishing: In this article, vishing refers to voice phishing attacks that use phone calls to deceive individuals into revealing sensitive information.
- MFA: MFA, or multi-factor authentication, is a security measure that requires multiple forms of verification before granting access to accounts.
- ShinyHunters: ShinyHunters is a financially motivated hacking group known for conducting data breaches and extortion activities against organizations.
- UNC6661: UNC6661 is a cluster of threat activity identified by Mandiant, associated with vishing attacks targeting employee credentials.
- Credential Harvesting: Credential harvesting is the process of collecting user credentials, such as usernames and passwords, often through deceptive means.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.