Quick Summary
The Securityish Brief
The ShinyHunters group has recently shifted tactics, using multi-factor authentication (MFA) as a pretext in social engineering attacks. Companies such as Panera Bread, SoundCloud, and Match Group have been affected, with incidents reported in early to mid-January 2026. Threat actors impersonated IT staff over the phone, directing employees to enter their credentials and MFA codes into phishing sites designed to look like their employer’s.
In these attacks, groups like UNC6661 and UNC6671 have been identified as using similar methods to harvest credentials. For instance, UNC6661 posed as IT personnel to direct employees to credential harvesting sites, capturing both SSO credentials and MFA codes. This allowed them to register their own devices for MFA, gaining unauthorized access to accounts, including those belonging to Okta customers.
Once inside the victim’s environment, attackers searched for sensitive documents containing personally identifiable information and other confidential terms. They also attempted to cover their tracks by deleting security-related emails and phishing messages from compromised accounts.
UNC6671 utilized similar tactics, leading victims to phishing sites where they entered their credentials and MFA codes. After accessing Okta accounts, they employed PowerShell to download sensitive data from platforms like SharePoint and OneDrive.
These coordinated attacks highlight the evolving nature of cyber threats, particularly in how MFA is being manipulated. Organizations across various sectors, including tech, fintech, healthcare, and retail, are at risk as researchers have detected ongoing targeting efforts.
Understanding the Threat Landscape
As the ShinyHunters group continues to exploit MFA, organizations must recognize the potential for similar attacks. The use of voice phishing, or vishing, combined with phishing kits allows attackers to synchronize authentication flows, making it easier to bypass security measures. The implications for data security and privacy are significant, as attackers can exfiltrate sensitive information and engage in extortion tactics.
Organizations should be proactive in monitoring for signs of these attacks, including unusual login attempts and unauthorized access to sensitive data. Implementing robust security measures, such as employee training on recognizing phishing attempts and enhancing MFA protocols, can help mitigate risks associated with these evolving threats.
- Panera Bread: Targeted by ShinyHunters in recent social engineering attacks.
- SoundCloud: Another victim of the MFA exploitation tactics employed by the attackers.
- Match Group: Owner of dating services like Tinder and Hinge, affected by the ongoing threats.
- UNC6661: A group impersonating IT staff to harvest credentials and MFA codes.
- UNC6671: Similar tactics used to gain access to Okta customer accounts and sensitive data.
Key Takeaways
- Train employees to recognize phishing attempts and verify requests for sensitive information.
- Implement enhanced MFA protocols that require more than just codes sent via SMS or email.
- Monitor for unusual login attempts and unauthorized access to sensitive data.
- Regularly review and update security policies to address emerging threats.
- Consider using security tools that provide alerts for suspicious activities related to MFA.
Key Terms & Concepts
- Multi-Factor Authentication (MFA): In this article, MFA refers to a security measure that requires multiple forms of verification to access accounts.
- Phishing: Phishing is a cyber attack method where attackers impersonate legitimate entities to steal sensitive information.
- Social Engineering: Social engineering involves manipulating individuals into divulging confidential information through deceptive tactics.
- Vishing: Vishing is a form of phishing that uses phone calls to trick individuals into providing sensitive information.
- Credential Harvesting: Credential harvesting is the process of collecting usernames and passwords through deceptive means.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.