Canva among ~100 targets of ShinyHunters Okta identity-theft campaign
ShinyHunters has targeted around 100 organizations in a credential-stealing campaign involving Okta single sign-on accounts. Silent Push researchers reported that high-value enterprises, including Canva, Atlassian, and Epic Games, have been actively targeted. While no breaches have been confirmed, the campaign employs evolved voice-phishing techniques to compromise SSO credentials. Mandiant recommends organizations adopt phishing-resistant multi-factor authentication and monitor for unauthorized activities. ShinyHunters has claimed responsibility for the campaign, which has reportedly led to data leaks from Crunchbase and Betterment.
The Register·