ShinyHunters Stopped Stealing Vendor Tokens and Started Making Phone Calls. If You Prepared for Last Year, You Prepared Wrong.
- Patrick Duggan
- 14 minutes ago
- 4 min read
Brinks Home confirmed this week that its systems were breached. ShinyHunters claimed it, and claimed 4.9 million Salesforce records. Separately, Health-ISAC warned its members of a rise in successful ShinyHunters attacks against healthcare and medical technology organisations.
Two reports, independent of each other, describing the same method. And it is not the method we have spent a year documenting.
What our own corpus says ShinyHunters does
Everything we have published — the twelve-security-vendor piece, the Telus chain, the Salesloft anatomy — describes one technique:
Compromise Salesloft's GitHub between March and June 2025. Extract the OAuth tokens for the Drift and Drift Email integrations from source. Use those tokens to authenticate directly into 700-plus Salesforce tenants. Exfiltrate at scale.
The defining property of that attack is that the victim was never touched. No employee was contacted, nothing was clicked, no credential was surrendered. The vendor was compromised and the customers inherited it. It is a supply-chain attack that happens to end in a CRM.
That is what we told people to defend against: audit your OAuth integrations, know what your vendors can reach, treat an installed app as a standing credential.
What is being reported now
Brinks Home identified the intrusion on 20 July. The claimed route is voice phishing against Microsoft Entra — call an employee, talk them out of their single-sign-on credentials, use the account, pivot into the cloud estate.
Health-ISAC describes the same shape independently: ShinyHunters vished multiple employees, compromised a Microsoft Entra SSO account, and took data from Microsoft 365, SharePoint and other enterprise platforms.
No stolen vendor token. No supply-chain compromise. No 700 tenants in one motion. A phone call, to a person, that scales by dialling more people.
Why the corroboration matters more than the claim
We have written repeatedly that a ShinyHunters leak-site post is not evidence — the name has become a brand worn by unrelated crews, and we have called their claims false before when the tradecraft didn't hold up.
So the reason this one is worth publishing is not that they claimed it. It is that two unrelated parties describe the same technique in the same fortnight: a named company confirming an intrusion, and a sector ISAC warning its members from separate incident reporting. That is corroboration, and it is the standard we said we would hold ourselves to.
What we are not saying is that these are the same operators as 2025. The technique changed completely, the name is known to be shared, and nobody has published evidence linking the two. A crew that vishes helpdesks and a crew that raids a vendor's GitHub are different capabilities. They may be the same people who changed method. They may not be. Unresolved, and we will not pretend otherwise.
The part that costs defenders money
If you spent the last year hardening against the 2025 technique — OAuth inventories, connected-app reviews, vendor-integration audits — that work was correct and you should keep it. It does nothing against this.
A vishing attack on Entra defeats an OAuth inventory completely, because no app is installed and no token is stolen. The attacker logs in as your employee, through your front door, with credentials your employee handed over voluntarily. Every control you built for the vendor-compromise scenario sits to one side and watches.
The controls that actually bite here are different and mostly unglamorous:
Phishing-resistant MFA. Not push notifications — those are what vishing defeats, by talking the target through approving one. FIDO2 or certificate-based. This is the single highest-value change and it is the one most organisations keep deferring.
Help-desk identity verification. The attack frequently runs through your service desk, not just at your users. If somebody can call your help desk and get an MFA reset with information available on LinkedIn, your MFA is decorative.
Alert on impossible travel and new-device SSO into M365, and treat a first-time sign-in from an unusual location as an event rather than a log line.
Restrict who can grant consent and who can register devices, because the pivot after the initial login is what turns one credential into a data set.
The uncomfortable pattern
We have now watched this crew's brand move from stealing a vendor's source-control secrets to phoning employees. Both work. Both produced millions of records. The second requires vastly less skill.
That is the direction of travel worth noticing: as identity became the perimeter, the cheapest attack on the perimeter became a conversation. Nothing about a phone call is sophisticated, and nothing about it is stopped by the security programme you built for supply-chain risk.
If you run a healthcare or medtech organisation, Health-ISAC's warning is the one to act on this week — the sector is being worked deliberately.
Confidence capped at 95%. The Brinks Home intrusion date and confirmation are from the company's own statements and contemporaneous reporting; the technique details are as claimed by the actor and as separately described by Health-ISAC. We hold no indicators from either incident and no first-party visibility. Whether the 2026 activity shares operators with the 2025 Salesloft campaign is not established by anyone, including us.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
