ShinyHunters Are Phoning Hospital Help Desks: Health-ISAC Sounds the Alarm
A wave of voice-phishing calls is tricking healthcare staff into handing over single sign-on access, and the data theft is following fast.

Key points
- Health-ISAC, the information-sharing group for the healthcare industry, warned members this week of a rise in ShinyHunters attacks against hospitals and medical technology firms.
- The hackers are calling help desks and staff directly, posing as IT, to steal single sign-on logins that unlock cloud services like Salesforce, Workday and Microsoft 365.
- Stolen data is then used for extortion, with victims pressured to pay before the files are leaked or sold.
- Health-ISAC says multi-factor authentication alone has not stopped the crew, because staff are being talked into approving the login prompts themselves.
- The group overlaps with Scattered Spider and the recent Snowflake customer thefts, and has been active against retail, insurance and airline targets earlier this year.
A criminal group known as ShinyHunters has turned its attention to hospitals and medical technology companies, and it is getting in by picking up the phone.
Health-ISAC, the body that shares cyber threat information across the healthcare sector, told members this week that successful attacks are climbing fast. The warning was first reported by BleepingComputer.
The method is old-fashioned in a way that should embarrass the industry. The hackers call a help desk or a specific employee, pretend to be internal IT, and talk their way into a password reset or a fresh multi-factor prompt. Once they are in the single sign-on portal, which is the one login that opens every work app, they walk straight into the cloud services behind it.
How are the hackers getting in?
They are talking their way in, not hacking in. ShinyHunters is running voice phishing, known as vishing, against help desks and staff. The goal is a working single sign-on session, the master key that most companies now use to log people into everything from email to patient records.
Once the caller convinces a support agent to reset a password or enrol a new phone for multi-factor authentication (MFA), the game is over. MFA, the second check that normally sends a code or a push notification to your phone, does not help if the person approving the prompt is the attacker's new phone.
From there, the crew pulls data out of connected cloud platforms. Health-ISAC specifically flags Salesforce, Workday, and Microsoft 365 as targets, because those tenants often hold patient contact lists, HR records and internal email.
Who is ShinyHunters?
ShinyHunters is a long-running data extortion crew, best known for dumping stolen databases on criminal forums. Investigators say the current activity overlaps heavily with Scattered Spider, the English-speaking group behind the MGM and Caesars break-ins in 2023, and with the mass thefts from Snowflake customer accounts in 2024.
Whether these are the same people wearing different hats or a loose collective sharing tools, the playbook is identical: social engineering, cloud identity abuse, then extortion.
What does this mean for patients?
If your hospital or insurer is hit, the data most at risk is the kind held in cloud business apps: names, dates of birth, contact details, appointment information and sometimes billing records. Clinical systems on internal networks are usually not the first target.
Watch for unexpected emails or calls claiming to be from your provider, especially any that ask you to "confirm" details or click a link about a recent visit. If in doubt, hang up and call the number on the back of your insurance card.
What can hospitals actually do?
Health-ISAC's advice lands on the identity layer, and rightly so. The group recommends stricter help desk verification (video calls, manager callbacks, or in-person checks before any password or MFA reset), phishing-resistant MFA such as hardware keys or passkeys built on the FIDO2 standard, and tighter conditional access rules that block logins from unusual locations or unmanaged devices.
The honest reading: standard push-notification MFA is no longer enough on its own against a determined caller. Federated logins are only as strong as the person answering the help desk phone at 3am.



