
Share
A ransomware-turned-extortion crew is phoning healthcare workers directly, tricking them past login security to raid cloud systems. Health-ISAC says the window to shore up defenses is closing fast, and hospitals need to act now.
Picture a hospital IT worker's phone ringing on a Tuesday afternoon. The caller sounds like help desk staff, calm and official, explaining there's a login problem that needs immediate attention. Within minutes, that one phone call can open a door into a health system's most sensitive records: patient files, internal communications, financial data. This is not a hypothetical. It is happening right now, and the Health Information Sharing and Analysis Center is telling providers to treat it as an emergency.
Health-ISAC issued a threat bulletin warning that ShinyHunters, a cybercrime group best known for ransomware and impersonating IT support staff, is running an aggressive campaign against the healthcare sector worldwide. The group's method relies less on hacking code and more on hacking trust. Members call employees on their personal mobile devices, email them from a rotating cast of random accounts, then follow up with voicemails coaxing users to click links that bypass corporate security. It is social engineering dressed up in the language of routine IT maintenance, and it is working.
Think of it like a con artist who has studied your company's org chart. ShinyHunters registers domains carrying a target company's name, then tacks on convincing endings, such as ".claim," tailored to whatever story the phishing lure is telling. These look-alike sites are built to mirror legitimate company login portals closely enough that a distracted employee, especially one who just got a phone call from someone claiming to be IT, might not notice the difference.
Once someone enters their credentials on the fake site, the attackers do not just steal a password. Health-ISAC explains that the threat actors use reverse-proxy phishing kits, tools that quietly relay stolen credentials to the real corporate login portal in real time. It is a bit like a pickpocket who hands your wallet to an accomplice before you even notice it is gone. The victim, still on the phone, is then asked to provide their active multifactor authentication token or approve a push notification. That single approval hands the attacker a live, authenticated session, no further hacking required.
From there, the intrusion spreads laterally into whatever software-as-a-service platforms the compromised identity can reach: Microsoft 365, SharePoint, Salesforce. That is where the real damage happens, as attackers exfiltrate sensitive data and internal communications at scale.
The stakes became painfully concrete this past month. McKesson, the pharmaceutical and medical supply giant, disclosed a cybersecurity incident to the Securities and Exchange Commission affecting its Oncology & Multispecialty and Medical-Surgical business units. ShinyHunters claimed to have stolen 284 million patient records in that breach and demanded a $55 million ransom, after vishing two McKesson employees and pulling data out of Salesforce and Snowflake environments. Two phone calls. Hundreds of millions of records at risk. That ratio alone should worry every hospital security team.

ShinyHunters also claims to have compromised more than 400 websites by exploiting misconfigurations in publicly accessible sites built on Salesforce's Experience Cloud platform. Health-ISAC noted that the group's recent behavior looks less like classic ransomware, where files get encrypted and locked, and more like an identity- and SaaS-access extortion operation, where the leverage comes from stolen access itself rather than scrambled files. That distinction matters for defenders, because the tools that stop ransomware encryption do not necessarily stop someone from simply logging in as an authorized user and walking out the digital front door with data.
Health-ISAC's guidance is specific and actionable. Organizations should block certain top-level domains outright unless they are confirmed legitimate, since many of ShinyHunters' impersonation sites rely on obscure or unusual domain endings that a healthy skepticism, and some domain filtering, can catch early. The organization also recommends defense-in-depth architecture for identity verification, meaning no single control, not even MFA, should be the only thing standing between an attacker and a compromised account.
Perhaps most urgent is Health-ISAC's push toward phish-resistant multifactor authentication. Traditional MFA, the kind that sends a push notification or a one-time code, can be defeated by exactly the kind of real-time phishing kits ShinyHunters uses. Phish-resistant methods, often built on hardware security keys or device-bound credentials, are much harder to trick because they cannot simply be relayed through a fake login page. Alongside that technical shift, Health-ISAC is urging employee training focused specifically on spotting look-alike domains, and a strict, no-exceptions policy against resetting MFA credentials based on inbound phone calls, since that is precisely the pressure point ShinyHunters is exploiting.
Errol Weiss, Health-ISAC's chief security officer, has been sounding this alarm for a while. Writing last year about hospital defenses amid a surge in artificial intelligence-powered phishing, he argued that organizations need to treat every single login attempt as a potential threat and limit each user's access to only what they need at that particular moment. Strong authentication, tight role-based permissions, and continuous monitoring, he wrote, make it harder for intruders to move through systems undetected. That advice reads as even more urgent now that a live threat group is actively testing those defenses across the health sector.
Healthcare data breaches are not abstract. Behind every record ShinyHunters claims to have stolen sits a real patient, a real diagnosis, a real family history that was supposed to stay private. When attackers pivot from a single phishing call into full-scale exfiltration from platforms like Salesforce and Snowflake, the fallout lands on people who never picked up that phone and never clicked that link. Health-ISAC's blunt assessment says it plainly: this group is actively targeting the health sector and has repeatedly succeeded by bypassing multifactor authentication to pivot from single sign-on platforms into connected SaaS applications for large-scale data theft and extortion. Providers that wait for the next headline before acting are gambling with records they were trusted to protect.
Tags
Original Sources
Health-ISAC warns providers about ShinyHunters vishing campaign
↗ https://www.healthcareitnews.com/news/health-isac-warns-providers-about-shinyhunters-vishing-campaign
About the author
Amara's entry point into AI was an epidemiology role at a London research hospital, where she spent five years studying how digital health tools reached — or conspicuously failed to reach — underserved communities. Watching early algorithmic systems in healthcare quietly entrench existing inequalities, she redirected her career toward the systemic consequences of AI at scale. She covers AI through an unflinching lens: who benefits, who bears the cost, and what evidence actually says versus what the press release claims. Her writing is calm and precise, but she doesn't mistake balance for neutrality.
More from The Steward →This Week's Edition
11 September 2026
33 articles
Related Articles

Hugging Face Attack Signals Wider Risks in the AI Infrastructure Everyone Relies On
Security & Risk · 5 min

AI Enters the Exam Room: Federal Investment in Heart Failure Tools Meets Rural Health Skepticism
Health & Science · 5 min

Can AI Really Save Rural Hospitals Facing Nearly $1 Trillion in Medicaid Cuts?
Job Market & Society · 5 min
Related Articles

Hugging Face Attack Signals Wider Risks in the AI Infrastructure Everyone Relies On
Security & Risk · 5 min

AI Enters the Exam Room: Federal Investment in Heart Failure Tools Meets Rural Health Skepticism
Health & Science · 5 min

Can AI Really Save Rural Hospitals Facing Nearly $1 Trillion in Medicaid Cuts?
Job Market & Society · 5 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.