Signal

ShinyHunters claims SSO vishing campaign tied to SaaS data theft and extortion

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-01-23 18:46 UTCUpdated 2026-01-24 12:00 UTC
rss
extortionvishingssooktamicrosoftgoogle
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
Overview

Multiple outlets report that ShinyHunters is publicly claiming responsibility for an ongoing wave of voice-phishing (vishing) attacks aimed at stealing single sign-on (SSO) access tied to major identity/SaaS ecosystems. The reporting frames the objective as gaining entry to corporate SaaS environments to steal data for extortion, alongside separate claims of Okta-related customer breaches and data leaks.

Score total
1.35
Momentum 24h
3
Evidence documents
-
Independent publishers
-
Independent origins
-
Primary sources
-
Secondary sources
-
Source types
-
Duplicate ratio
0%
Why now
  • Multiple outlets are reporting ShinyHunters’ claim of responsibility for the SSO-focused vishing wave.
  • Separate coverage links the claims to alleged Okta-customer breaches and data leaks.
  • Reports describe the campaign as ongoing rather than a single isolated incident.
Why it matters
  • Vishing against SSO can enable broad access to corporate SaaS environments.
  • The activity is framed as data theft for extortion, increasing operational and legal risk.
  • Claims of additional victims suggest potential ongoing exposure beyond initial reports.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • ShinyHunters claims it is behind ongoing vishing attacks targeting SSO accounts at Okta, Microsoft, and Google to access corporate SaaS and steal data for extortion.
  • ShinyHunters claims Okta customer breaches and says more victims are coming, with reporting describing alleged access to Crunchbase and Betterment and data leaks affecting three organizations.
How sources frame it
  • BleepingComputer: neutral
  • DataBreaches.net: neutral
  • The Register: neutral
Coverage centers on ShinyHunters’ self-attributed vishing activity against SSO and related breach/leak claims; treat attribution as claimed unless independently confirmed.
All evidence
All evidence
ShinyHunters claim to be behind SSO-account data theft attacks
Databreaches · databreaches.net · 2026-01-24 12:00 UTC
ShinyHunters claim to be behind SSO-account data theft attacks
BleepingComputer · bleepingcomputer.com · 2026-01-23 23:35 UTC
ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs
Theregister · go.theregister.com · 2026-01-23 18:46 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 3
Top publishers (this list)
  • Databreaches (1)
  • BleepingComputer (1)
  • Theregister (1)
Top origin domains (this list)
  • databreaches.net (1)
  • bleepingcomputer.com (1)
  • go.theregister.com (1)