ShinyHunters Are Phoning Hospital Help Desks: Health-ISAC Sounds the Alarm
A wave of voice-phishing calls is tricking healthcare staff into handing over single sign-on access, and the data theft is following fast.

Key points
- Health-ISAC, the information-sharing group for the healthcare industry, warned members this week of a rise in ShinyHunters attacks against hospitals and medical technology firms.
- Attackers are calling help desks and staff directly, posing as internal IT, to steal single sign-on credentials that open cloud platforms including Salesforce and Workday.
- Stolen data is then used for extortion, with victims pressured to pay before files are leaked or sold.
- Health-ISAC says multi-factor authentication alone hasn't stopped the crew, because staff are being talked into approving the login prompts themselves.
- The group overlaps with Scattered Spider and the recent Snowflake customer thefts, and has been active against retail, insurance and airline targets earlier this year.
A criminal group known as ShinyHunters has turned its attention to hospitals and medical technology companies, getting in by picking up the phone.
Health-ISAC, the body that shares cyber threat information across the healthcare sector, told members this week that successful attacks are climbing. BleepingComputer first reported the warning. We covered ShinyHunters' impact on healthcare in early July, when Medtronic confirmed the group had rifled through its systems for nearly a week, exposing names, Social Security numbers and health details.
The method is embarrassingly low-tech. Callers pretend to be internal IT, talk a support agent into a password reset or a fresh authentication enrolment, and they're inside.
How are the hackers getting in?
They're talking their way in. ShinyHunters is running voice phishing, known as vishing, against help desks. The goal is a working single sign-on session: the master credential most organisations now use to log staff into everything from email to patient records.
Once a caller convinces an agent to reset a password or enrol a new device for multi-factor authentication (MFA, the second check that normally sends a code or push notification to your phone), the protection evaporates. MFA doesn't help if the person approving the prompt is holding the attacker's new phone.
From there, the crew pulls data out of connected cloud platforms. Health-ISAC specifically flags Salesforce and Workday as targets, because those tenants often hold patient contact lists and HR records.
Who is ShinyHunters?
ShinyHunters is a long-running data extortion crew, best known for dumping stolen databases on criminal forums. Investigators say the current activity overlaps heavily with Scattered Spider, the English-speaking group behind the MGM and Caesars break-ins in 2023, and with the mass thefts from Snowflake customer accounts in 2024.
Whether these are the same people wearing different hats or a loose collective sharing tools, the playbook is identical: social engineering, cloud identity abuse, then extortion.
What does this mean for patients?
If your hospital or insurer is hit, the data most at risk is the kind held in cloud business apps: names, dates of birth, contact details and billing records. Clinical systems on internal networks aren't usually the first target.
Watch for unexpected emails or calls claiming to be from your provider, especially any asking you to confirm details about a recent visit. Call the number on the back of your insurance card if something feels off.
Should you worry about the help desk specifically?
Yes, and Health-ISAC's advice lands squarely on the identity layer. The group recommends stricter help desk verification, video calls or manager callbacks before any password or MFA reset, phishing-resistant MFA such as hardware keys or passkeys built on the FIDO2 standard, and conditional access rules that block logins from unusual locations or unmanaged devices.
This vishing approach isn't novel. A similar crew called Helix was doing the same thing to SharePoint files just weeks ago, and the pattern keeps working because federated logins are only as strong as whoever answers the help desk phone at 3am. Standard push-notification MFA is no longer sufficient against a patient, well-scripted caller.


