ShinyHunters Targets Healthcare with Aggressive Vishing Campaigns

Healthcare Sector Faces Surge in Social Engineering & Vishing Attacks

HIGH
September 25, 2026
5m read
PhishingThreat ActorCyberattack

Full Report

Executive Summary

Cybersecurity researchers and the Health Information Sharing and Analysis Center (Health-ISAC) are sounding the alarm over a significant increase in social-engineering attacks targeting the healthcare and pharmaceutical sectors. Threat actors, including the well-known group ShinyHunters, are employing aggressive voice phishing (vishing) campaigns to manipulate employees into compromising their credentials and multi-factor authentication (MFA) protections. These attacks leverage medical-themed impersonation domains to appear legitimate and often involve belligerent phone calls to pressure targets. The trend indicates a strategic shift by attackers to use operational downtime as a key pressure point for extortion, recognizing the critical nature of clinical workflows.


Threat Overview

The recent campaigns represent a targeted effort against a vulnerable and high-value sector. According to Health-ISAC, over a dozen of its member organizations have been impacted in the last two months. Attackers are moving beyond simple email phishing to direct, interactive social engineering over the phone (T1598 - Phishing for Information).

The goal is to trick an employee, often in IT help desk or support roles, into initiating a password or MFA reset. The attacker, posing as a legitimate user, directs the target to a malicious domain designed to capture credentials or session tokens. The use of "belligerent" tactics suggests attackers are using intimidation and creating a sense of urgency to force compliance.

Researchers at Unit 42 have linked the domain my-passkeys[.]com to The Com, an underground cybercrime network, suggesting it is part of the infrastructure used in these attacks. This sustained focus on healthcare indicates that threat actors view the sector's reliance on constant uptime as a powerful lever for extortion.

Technical Analysis

The attack chain is centered on human manipulation rather than technical exploits:

  1. Reconnaissance: Attackers gather contact information for employees, likely from professional networking sites like LinkedIn or from previous data breaches.
  2. Infrastructure Setup: Malicious domains are registered that impersonate legitimate services (e.g., my-passkeys[.]com). These domains host phishing kits designed to harvest credentials and MFA tokens (T1566.002 - Spearphishing Link).
  3. Initial Contact (Vishing): The attacker calls the target, impersonating a user in distress. They use social engineering to create a pretext for an urgent password or MFA reset.
  4. Credential Theft: The target is directed to the malicious site, where they enter their credentials. If MFA is in place, the attacker may attempt to capture a one-time code or trick the user into approving a push notification (MFA Fatigue).
  5. Initial Access: With compromised credentials, the attacker gains access to the organization's network, VPN, or cloud applications (T1078 - Valid Accounts).

Impact Assessment

The primary impact of these attacks is operational disruption. For healthcare organizations, any system downtime can directly affect patient care, leading to canceled appointments, delayed procedures, and potential risks to patient safety. This makes the sector uniquely susceptible to extortion tactics that threaten downtime. While data theft remains a concern, the immediate threat of disrupting clinical workflows is a powerful weapon. The targeting of over a dozen Health-ISAC members indicates a widespread and systematic campaign that poses a significant risk to the entire healthcare and pharmaceutical supply chain.

IOCs — Directly from Articles

Type
domain
Value
my-passkeys[.]com
Description
Phishing domain associated with 'The Com' network targeting healthcare.

Cyber Observables — Hunting Hints

Security teams may want to hunt for the following patterns to detect related activity:

Type
url_pattern
Value
*/my-passkeys[.]com/*
Description
Any network traffic or proxy logs showing connections to this known malicious domain.
Type
log_source
Value
VPN/SSO Authentication Logs
Description
Look for multiple failed login attempts followed by a successful login and a password reset from the same account.
Type
log_source
Value
Help Desk Ticketing System
Description
Review tickets for password resets that were initiated via phone call and seem unusual or urgent.
Type
certificate_subject
Value
CN=*passkey* or CN=*sso*
Description
Search Certificate Transparency logs for newly registered domains containing keywords related to passwords, MFA, SSO, or passkeys, especially if they are typosquats of legitimate services.

Detection & Response

  • Enhanced Monitoring: Monitor for unusual MFA activity, such as multiple push notifications sent to a user in a short period (MFA fatigue) or MFA registration for a new device shortly after a password reset. D3FEND's D3-ANET: Authentication Event Thresholding can help detect such patterns.
  • Help Desk Protocol: Implement strict identity verification protocols for all help desk requests, especially those made over the phone that involve password or MFA resets. This should involve callback verification to a registered number or the use of pre-established security questions.
  • Network Blocking: Proactively block known malicious domains and IPs associated with these phishing campaigns at the firewall, proxy, and DNS levels. Use D3-DNSDL: DNS Denylisting.

Mitigation

  • User Training: Conduct regular, targeted security awareness training that specifically addresses vishing and social engineering tactics. Use simulations to train employees to recognize and report suspicious phone calls.
  • Phishing-Resistant MFA: Where possible, transition from push-based or SMS-based MFA to more secure, phishing-resistant methods like FIDO2/WebAuthn security keys. This is a key application of M1032 - Multi-factor Authentication.
  • Restrict Access: Enforce the principle of least privilege. Ensure that user accounts only have access to the data and systems necessary for their job roles to limit the impact of a compromised account.

Timeline of Events

1
September 25, 2026
This article was published

MITRE ATT&CK Mitigations

Train users to identify and report social engineering attempts, including vishing and MFA fatigue attacks.

Implement phishing-resistant MFA (e.g., FIDO2) to mitigate credential theft and MFA fatigue.

Mapped D3FEND Techniques:

Use web filtering and DNS security to block access to known phishing domains.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

To combat the vishing and MFA fatigue tactics used by ShinyHunters, healthcare organizations must prioritize the deployment of phishing-resistant Multi-Factor Authentication. Standard push-based authenticators are vulnerable to 'MFA fatigue,' where attackers spam the user with approval requests. Instead, organizations should deploy FIDO2/WebAuthn-compliant hardware security keys or platform authenticators (like Windows Hello or Touch ID). These methods require a physical interaction and cryptographic proof of presence, making it impossible for a remote attacker to approve a login even if they have the user's password. This should be mandated for all employees, with special priority for IT staff, administrators, and those with access to sensitive patient data or clinical systems.

Implement advanced monitoring and alerting for authentication events. Configure SIEM or IAM tools to generate high-priority alerts for patterns indicative of an attack. Specific rules should include: 1) Alerting on more than three MFA push requests to a single user within a 5-minute window. 2) Alerting on a successful password reset followed by a login from a new or unrecognized device/location within one hour. 3) Alerting on a successful login immediately after a series of failed attempts. These thresholds can serve as an early warning that a user is under active social engineering pressure, allowing security teams to intervene, lock the account, and contact the user through a secure, out-of-band channel.

Sources & References

Threat groups ramp up social-engineering attacks against healthcare sector
Cybersecurity Dive (cybersecuritydive.com) •September 25, 2026
Healthcare Cyberattacks Are Changing: Downtime Is the New Pressure Point
eSecurityPlanet (esecurityplanet.com) •September 24, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

social engineeringvishinghealthcarepharmaceuticalShinyHuntersHealth-ISACMFA fatigue

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.