Google’s Threat Intelligence Group (GTIG) and Mandiant have spotted a big rise in attacks linked to the ShinyHunters extortion group.
These cybercriminals use voice phishing (vishing) calls and fake login sites to steal single sign-on (SSO) credentials and multi-factor authentication (MFA) codes from employees.
Once inside company networks, they grab sensitive data from cloud apps like SharePoint, Salesforce, and DocuSign. Then, they demand ransom or leak the info on dark web sites.
This is not due to flaws in vendor software. It’s pure social engineering. GTIG tracks it under clusters UNC6661, UNC6671, and UNC6240.
The attacks hit more cloud platforms now, showing ShinyHunters wants richer data for bigger payoffs. They’ve added nasty tricks like harassing victims and DDoS attacks on company sites.
Vishing and Credential Theft Tactics
Threat actors pose as IT help desk staff. They call workers, claim MFA updates are needed, and send them to fake sites like <company>sso.com or <company>internal.com.
These domains often come from registrars like NICENIC or Tucows. Victims enter SSO logins and MFA codes, letting attackers register their own devices.
UNC6661 struck in early January 2026. They hit Okta users, then roamed to SaaS apps.
{
"AppAccessContext": {
"AADSessionId": "[REDACTED_GUID]",
"AuthTime": "1601-01-01T00:00:00",
"ClientAppId": "[REDACTED_APP_ID]",
"ClientAppName": "Microsoft Office",
"CorrelationId": "[REDACTED_GUID]",
"TokenIssuedAtTime": "1601-01-01T00:02:56",
"UniqueTokenId": "[REDACTED_ID]"
},
"CreationTime": "2026-01-10T13:17:11",
"Id": "[REDACTED_GUID]",
"Operation": "FileDownloaded",
"OrganizationId": "[REDACTED_GUID]",
"RecordType": 6,
"UserKey": "[REDACTED_USER_KEY]",
"UserType": 0,
"Version": 1,
"Workload": "SharePoint",
"ClientIP": "[REDACTED_IP]",
"UserId": "[REDACTED_EMAIL]",
"ApplicationId": "[REDACTED_APP_ID]",
"AuthenticationType": "OAuth",
"BrowserName": "Mozilla",
"BrowserVersion": "5.0",
"CorrelationId": "[REDACTED_GUID]",
"EventSource": "SharePoint",
"GeoLocation": "NAM",
"IsManagedDevice": false,
"ItemType": "File",
"ListId": "[REDACTED_GUID]",
"ListItemUniqueId": "[REDACTED_GUID]",
"Platform": "WinDesktop",
"Site": "[REDACTED_GUID]",
"UserAgent": "Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.20348.4294",
"WebId": "[REDACTED_GUID]",
"DeviceDisplayName": "[REDACTED_IPV6]",
"EventSignature": "[REDACTED_SIGNATURE]",
"FileSizeBytes": 31912,
"HighPriorityMediaProcessing": false,
"ListBaseType": 1,
"ListServerTemplate": 101,
"SensitivityLabelId": "[REDACTED_GUID]",
"SiteSensitivityLabelId": "",
"SensitivityLabelOwnerEmail": "[REDACTED_EMAIL]",
"SourceRelativeUrl": "[REDACTED_RELATIVE_URL]",
"SourceFileName": "[REDACTED_FILENAME]",
"SourceFileExtension": "xlsx",
"ApplicationDisplayName": "Microsoft Office",
"SiteUrl": "[REDACTED_URL]",
"ObjectId": "[REDACTED_URL]/[REDACTED_FILENAME]"
}
Logs show downloads from SharePoint via PowerShell, Salesforce logins from suspicious IPs, and DocuSign envelope grabs.
In one case, they turned on ToogleBox Recall in Google Workspace to delete Okta’s “new MFA device” emails, hiding their tracks.
UNC6671 used similar vishing but different domain registrars. They also pulled SharePoint data with PowerShell.
After theft, UNC6661 sent phishing emails from stolen accounts to crypto firms, then deleted them. UNC6240 handles extortion, using Tox chats, BTC demands, and LimeWire samples.
A new “SHINYHUNTERS” leak site lists victims with emails like shinycorp@tutanota.com.
| Phishing Domain Patterns | Examples (Defanged) |
|---|---|
| Corporate SSO | <company>sso[.]com, my<company>sso[.]com |
| Internal Portals | <company>internal[.]com, www.<company>internal[.]com |
| Support/Helpdesk | <company>support[.]com, support-<company>[.]com |
| Identity Providers | <company>okta[.]com, <company>azure[.]com |
| Access Portal | <company>access[.]com, my<company>access[.]com |
Data Exfiltration and Extortion Escalation
Attackers search cloud apps for keywords like “poc,” “confidential,” “salesforce,” or “vpn.” They target PII in Salesforce and Slack chats.
Extortion notes give 72-hour deadlines, BTC addresses, and threats. UNC6671 skips ShinyHunters branding but harasses staff.
.webp)
IPs tie to VPNs like Mullvad, Oxylabs, and proxies. Google added phishing domains to Chrome Safe Browsing.
| Key Network IOCs | ASN | Association |
|---|---|---|
| 24.242.93[.]122 | 11427 | UNC6661 |
| 73.135.228[.]98 | 33657 | UNC6661 |
| 76.64.54[.]159 | 577 | UNC6671 |
| 142.127.171[.]133 | 577 | UNC6671 |
Switch to phishing-resistant MFA like FIDO2 keys or passkeys. They beat SMS or push alerts.
Monitor Okta for admin role changes from anonymized IPs, SharePoint bulk downloads via PowerShell, and ToogleBox auths.
Google Security Operations has rules like “Okta Suspicious Actions from Anonymized IP” and SharePoint high-volume queries.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google



