Bottom line: ShinyHunters poses a significant threat to the global health sector with targeted attacks and compromised credentials.
What's happening: Health-ISAC has identified ShinyHunters as the primary attacker group, targeting hospitals and healthcare organizations worldwide, including the Cleveland Clinic and the University of California, San Francisco. ShinyHunters has demonstrated expertise in vishing, credential theft, and MFA bypass tactics, using spear phishing attacks on the Microsoft Office suite. The attacks have resulted in the successful compromise of sensitive information and systems, including those running version 2019 of the Microsoft Office suite.
What to do: Security leaders should prioritize monitoring for ShinyHunters activity, and implement MFA for all users on systems running version 2019 of the Microsoft Office suite to prevent similar attacks. Regularly review and update security policies to ensure compliance with the latest security standards and best practices.