Healthcare organisations worldwide are being warned about targeted ShinyHunters campaigns using voice phishing, impersonation domains and MFA bypass techniques to gain access to corporate identities and connected SaaS platforms.
Health-ISAC has issued an urgent threat alert warning healthcare organisations worldwide that the ShinyHunters cybercrime group is actively targeting the sector through sophisticated voice phishing and domain impersonation campaigns.
The organisation said several healthcare companies have been targeted by persistent vishing campaigns designed to trick employees into entering their credentials on malicious websites that closely resemble legitimate corporate login portals.
Health-ISAC said the group has successfully bypassed multi-factor authentication (MFA) in several recent cases, enabling attackers to move from compromised single sign-on (SSO) accounts into connected SaaS applications and exfiltrate large volumes of data.
Attackers have been observed contacting employees directly on personal mobile devices through telephone calls and voicemails, while also distributing emails from multiple accounts.
The campaigns use lookalike domains incorporating the targeted company’s name, including addresses following patterns such as ‘company-claims’ or ‘company.claims’. Health-ISAC said the recent registration of medical-themed domains indicates an expanding focus on healthcare operations and specialist business units.
Attackers may conduct detailed reconnaissance on employees and internal departments before making contact. They can then impersonate IT help desks, legal teams or other internal functions and spoof known organisational telephone numbers to increase the credibility of their approach.
Victims can be pressured to visit malicious links on personal devices and enter corporate credentials. Reverse-proxy phishing technology can then relay those credentials to the genuine corporate login service in real time.
The attacker subsequently attempts to obtain an active MFA token or persuade the employee to approve a push notification, providing access to the victim’s account.
Once an identity is compromised, Health-ISAC said ShinyHunters can pivot through the organisation’s identity provider into connected services including Microsoft 365, SharePoint and Salesforce, where sensitive information and internal communications can be stolen for use in extortion.
Health-ISAC is recommending healthcare organisations move towards phishing-resistant MFA, strengthen helpdesk identity verification, monitor lookalike domains, restrict sensitive services to managed corporate devices and provide employees with targeted training around modern vishing techniques.

