Cybersecurity researchers and the Health Information Sharing and Analysis Center (Health-ISAC) are sounding the alarm over a significant increase in social-engineering attacks targeting the healthcare and pharmaceutical sectors. Threat actors, including the well-known group ShinyHunters, are employing aggressive voice phishing (vishing) campaigns to manipulate employees into compromising their credentials and multi-factor authentication (MFA) protections. These attacks leverage medical-themed impersonation domains to appear legitimate and often involve belligerent phone calls to pressure targets. The trend indicates a strategic shift by attackers to use operational downtime as a key pressure point for extortion, recognizing the critical nature of clinical workflows.
The recent campaigns represent a targeted effort against a vulnerable and high-value sector. According to Health-ISAC, over a dozen of its member organizations have been impacted in the last two months. Attackers are moving beyond simple email phishing to direct, interactive social engineering over the phone (T1598 - Phishing for Information).
The goal is to trick an employee, often in IT help desk or support roles, into initiating a password or MFA reset. The attacker, posing as a legitimate user, directs the target to a malicious domain designed to capture credentials or session tokens. The use of "belligerent" tactics suggests attackers are using intimidation and creating a sense of urgency to force compliance.
Researchers at Unit 42 have linked the domain my-passkeys[.]com to The Com, an underground cybercrime network, suggesting it is part of the infrastructure used in these attacks. This sustained focus on healthcare indicates that threat actors view the sector's reliance on constant uptime as a powerful lever for extortion.
The attack chain is centered on human manipulation rather than technical exploits:
my-passkeys[.]com). These domains host phishing kits designed to harvest credentials and MFA tokens (T1566.002 - Spearphishing Link).T1078 - Valid Accounts).The primary impact of these attacks is operational disruption. For healthcare organizations, any system downtime can directly affect patient care, leading to canceled appointments, delayed procedures, and potential risks to patient safety. This makes the sector uniquely susceptible to extortion tactics that threaten downtime. While data theft remains a concern, the immediate threat of disrupting clinical workflows is a powerful weapon. The targeting of over a dozen Health-ISAC members indicates a widespread and systematic campaign that poses a significant risk to the entire healthcare and pharmaceutical supply chain.
domainmy-passkeys[.]comSecurity teams may want to hunt for the following patterns to detect related activity:
url_pattern*/my-passkeys[.]com/*log_sourceVPN/SSO Authentication Logslog_sourceHelp Desk Ticketing Systemcertificate_subjectCN=*passkey* or CN=*sso*D3-ANET: Authentication Event Thresholding can help detect such patterns.D3-DNSDL: DNS Denylisting.M1032 - Multi-factor Authentication.Train users to identify and report social engineering attempts, including vishing and MFA fatigue attacks.
Implement phishing-resistant MFA (e.g., FIDO2) to mitigate credential theft and MFA fatigue.
Mapped D3FEND Techniques:
Use web filtering and DNS security to block access to known phishing domains.
To combat the vishing and MFA fatigue tactics used by ShinyHunters, healthcare organizations must prioritize the deployment of phishing-resistant Multi-Factor Authentication. Standard push-based authenticators are vulnerable to 'MFA fatigue,' where attackers spam the user with approval requests. Instead, organizations should deploy FIDO2/WebAuthn-compliant hardware security keys or platform authenticators (like Windows Hello or Touch ID). These methods require a physical interaction and cryptographic proof of presence, making it impossible for a remote attacker to approve a login even if they have the user's password. This should be mandated for all employees, with special priority for IT staff, administrators, and those with access to sensitive patient data or clinical systems.
Implement advanced monitoring and alerting for authentication events. Configure SIEM or IAM tools to generate high-priority alerts for patterns indicative of an attack. Specific rules should include: 1) Alerting on more than three MFA push requests to a single user within a 5-minute window. 2) Alerting on a successful password reset followed by a login from a new or unrecognized device/location within one hour. 3) Alerting on a successful login immediately after a series of failed attempts. These thresholds can serve as an early warning that a user is under active social engineering pressure, allowing security teams to intervene, lock the account, and contact the user through a secure, out-of-band channel.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.