// OktaHIGH
ShinyHunters extortion group is actively targeting healthcare organizations in a vishing campaign to reset Okta SSO credentials and MFA. Attackers impersonate employees to trick help desks into performing password resets, granting legitimate access to Okta accounts and downstream cloud platforms like Microsoft 365 and SharePoint for data exfiltration. Health-ISAC issued a major advisory on July 24, 2026 warning of this attack pattern.
// Get alerts for Okta