Health-ISAC Warns Healthcare Organizations About Increased ShinyHunters Data Theft Attacks

Health sector organizations have been warned about an increase in successful cyberattacks conducted by the ShinyHunters threat group, which targets cloud software-as-a-service platforms and cloud storage environments to steal data and demand ransom payments following large-scale data exfiltration.

Attack Methods

A recent cybersecurity alert from Health-ISAC states that ShinyHunters uses supply chain and identity attacks rather than ransomware. The group focuses on cloud-scale data exfiltration. Initial access is typically obtained through voice-based social engineering, also known as vishing, to persuade targets to reset passwords, reset multi-factor authentication, or enroll new devices.

After obtaining account access, the attackers log into an organization’s Okta, Microsoft Entra, or Google single sign-on dashboard. Those platforms provide visibility into applications available to the compromised account, including Microsoft 365, Salesforce, Dropbox, Google Drive, and other third-party services. Data is then rapidly exfiltrated. Victims are informed that data has been stolen and are asked to pay a ransom to prevent publication of the information on the group’s dark web data leak site.

Healthcare Organizations Affected

The alert states that ShinyHunters has launched successful attacks in recent months against multiple healthcare and medical technology organizations. Organizations identified in the alert include Medtronic, iRhythm, OneMedical, DentaQuest, AdaptHealth, and Him & Hers.

Health-ISAC also described a recent incident involving a health sector organization in which the threat group claimed to have conducted vishing attacks against multiple employees. According to the alert, those attacks resulted in the compromise of a Microsoft Entra account and the exfiltration of a substantial volume of company data from software-as-a-service platforms and internal services, including Microsoft 365 and SharePoint.

Recommended Helpdesk and Identity Controls

Health-ISAC advises healthcare and medical technology organizations to interrupt the attack sequence between the initial vishing call and the compromise of a single sign-on account.

The alert recommends strengthening helpdesk and identity and access management support procedures by requiring out-of-band identity verification before completing password resets, multi-factor authentication resets, or device reenrollment requests. Verification procedures should include a callback to a previously verified telephone number and manager approval for privileged users. Password resets, multi-factor authentication resets, and device reenrollment should not be completed during the same inbound telephone call that initiated the request.

Multi-Factor Authentication Protections

The alert recommends implementing phishing-resistant multi-factor authentication, including FIDO2, WebAuthn security keys, or equivalent technologies, for administrators and other high-risk groups, with deployment for all users identified as the preferred approach.

Health-ISAC also recommends disabling or tightly restricting SMS and voice-based multi-factor authentication along with other weak fallback methods. The alert advises organizations to apply strict controls to multi-factor authentication factor registration.

Protecting Single Sign-On Systems

Health-ISAC recommends treating single sign-on systems as Tier 0 assets because they provide access to numerous cloud services.

The alert recommends requiring multi-factor authentication and compliant devices to access sensitive cloud services, blocking legacy authentication, restricting administrative portals to managed devices, and implementing geo-velocity and impossible travel checks.

Monitoring for Data Exfiltration

Health-ISAC states that extortion depends on successful data exfiltration and recommends close monitoring for indicators of account compromise and large-scale data access.

The alert recommends centralizing Microsoft Entra sign-in logs, audit logs, and software-as-a-service audit logs within a security information and event management platform. Recommended alerting includes new device enrollments, multi-factor authentication factor registration OAuth reset events, new OAuth applications, unusual bulk downloads, unusual consent grants, new forwarding rules, atypical API activity, and mailbox delegation changes.

Workforce Awareness

Health-ISAC advises healthcare organizations to include vishing in HIPAA compliance and security awareness training because employees may be more familiar with traditional phishing attacks than voice-based social engineering.

The alert also recommends conducting vishing simulations for the workforce, with attention to privileged account holders, new employees, remote workers, and helpdesk information technology staff.

Recommended Implementation Timeline

Health-ISAC recommends implementing the mitigation measures within 30 to 60 days. Identify phishing-resistant multi-factor authentication for high-risk users. Consider conditional access policy enforcement as initial priorities. Strengthen helpdesk reset procedures. The organization also recommends conducting tabletop exercises focused on containing compromised cloud accounts through token and session revocation.

Author: Joe Murray

Joe Murray is the Editor-in-Chief of HIPAA 101, where he leads the writing team in delivering high-quality news and insights on HIPAA regulations. With over 15 years of experience in healthcare journalism, Joe has established himself as a trusted writer. At HIPAA 101, Joe is dedicated to providing healthcare professionals and administrative staff with accurate, timely, and comprehensive information to help them navigate the complexities of HIPAA.