---
title: "Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft"
metaTitle: "ShinyHunters-Branded SaaS Data Theft Expanding"
description: "Mandiant warns of an increase in vishing attacks linked to ShinyHunters, targeting SSO and SaaS apps, driving data theft and aggressive extortion campaigns."
slug: vishing-for-access
date: "2026-01-30T12:00:00-05:00"
featured: true
image:
  src: "https://cdn.securelogix.dev/slx/images/vishing-for-access.webp"
  alt: "A man's hand magically sucking credentials out of an open laptop."
sourcePublisher:
  name: Google Threat Intelligence
  url: "https://cloud.google.com/blog/topics/threat-intelligence/"
sourceArticle:
  url: "https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft"
tags: ["Vishing", "Tech Support Scam", "Credential Harvesting"]
status: published
---

Mandiant has identified an expansion in threat activity that uses tactics, techniques, and procedures (TTPs) consistent with prior ShinyHunters-branded extortion operations. These operations primarily leverage sophisticated voice phishing (vishing) and victim-branded credential harvesting sites to gain initial access to corporate environments by obtaining single sign-on (SSO) credentials and multi-factor authentication (MFA) codes. Once inside, the threat actors target cloud-based software-as-a-service (SaaS) applications to exfiltrate sensitive data and internal communications for use in subsequent extortion demands.

Google Threat Intelligence Group (GTIG) is currently tracking this activity under multiple threat clusters (UNC6661, UNC6671, and UNC6240) to enable a more granular understanding of evolving partnerships and account for potential impersonation activity. While this methodology of targeting identity providers and SaaS platforms is consistent with our prior observations of threat activity preceding ShinyHunters-branded extortion, the breadth of targeted cloud platforms continues to expand as these threat actors seek more sensitive data for extortion. Further, they appear to be escalating their extortion tactics with recent incidents including harassment of victim personnel, among other tactics.This activity is not the result of a security vulnerability in vendors' products or infrastructure. Instead, it continues to highlight the effectiveness of social engineering...
