Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
voice-social-engineeringidentity-authentication-vulnerabilityphishing-campaign-intelligencecybercrime-service-ecosystem

Okta Warns of Real-Time Vishing Phishing Kits Targeting SSO and MFA

Updated 1mo agoFirst seen Jan 23, 202617 sources

Okta reported that threat actors are using and selling custom voice-phishing (vishing) kits that enable helpdesk-style social engineering to steal credentials and bypass MFA for Okta SSO and other identity providers, including Google and Microsoft. The kits are offered “as a service” on dark web forums and messaging platforms and are designed to closely mimic legitimate identity-provider authentication flows, making the victim experience appear authentic during a live phone call.

Unlike static phishing pages, the kits function as adversary-in-the-middle platforms that let attackers monitor a victim’s session in real time and dynamically change what the victim sees (e.g., dialogs prompting for credentials or MFA approval) as the call progresses. Okta said operators typically conduct reconnaissance on targeted employees (names, applications used, and IT/helpdesk phone numbers), then call victims—often with spoofed corporate/helpdesk numbers—while guiding them through a tailored phishing page; captured credentials and MFA responses are relayed to the attacker to complete login and enable downstream data theft and extortion activity, echoing prior “IT support call” tradecraft associated with Scattered Spider-like intrusions.

Share:
Okta Warns of Real-Time Vishing Phishing Kits Targeting SSO and MFA
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
May 15, 20261mo ago

GTIG identifies UNC6671/BlackFile as distinct vishing-extortion actor

Google Threat Intelligence Group reported that UNC6671, operating under the BlackFile brand, has run a large-scale vishing and SSO-compromise extortion campaign since early 2026 against organizations in North America, Australia, and the UK. GTIG assessed the actor is distinct from ShinyHunters and described tradecraft including AiTM credential theft during live calls, attacker-controlled MFA enrollment, and automated SaaS data exfiltration from Microsoft 365, Okta-linked environments, SharePoint, OneDrive, Zendesk, and Salesforce.

Welcome to BlackFile: Inside a Vishing Extortion Operation | Google Cloud Blog
Apr 16, 20262mo ago

Abnormal reports ATHR AI-powered vishing platform

Abnormal disclosed a new cybercrime platform called ATHR that automates telephone-oriented attack delivery and voice-phishing campaigns using spoofed emails, telephony routing, and AI voice agents impersonating support staff. The service was advertised on underground forums for $4,000 plus a 10% commission and targeted accounts at providers including Google, Microsoft, and major cryptocurrency platforms.

New ATHR vishing platform uses AI voice agents for automated attacks
Jan 26, 20265mo ago

Silent Push reports 100+ organizations targeted in SSO vishing campaign

Silent Push reported a large-scale, active campaign targeting more than 100 high-value enterprises through live phishing panels and voice-phishing attacks against Okta and other SSO systems. The firm attributed the activity to an alliance it called 'SLSH,' linking tactics associated with Scattered Spider, LAPSUS$, and ShinyHunters.

Jan 23, 20265mo ago

Crunchbase confirms document exfiltration and contacts law enforcement

In related reporting tied to ShinyHunters' relaunch of its leak site, Crunchbase confirmed a document exfiltration incident from its corporate network. The company said it engaged outside experts and notified federal law enforcement.

ShinyHunters claims responsibility for the SSO-focused vishing campaign

ShinyHunters told BleepingComputer it was behind the ongoing wave of vishing attacks targeting Okta, Microsoft Entra, and Google-linked SSO accounts, and said Salesforce was its primary target. The claim connected the campaign's extortion phase to a named threat actor, though broader reporting still described multiple actors using similar kits.

Jan 22, 20265mo ago

Okta details post-compromise data theft and extortion pattern

Public reporting on Okta's findings said attackers used compromised Okta dashboards to enumerate connected SaaS apps, with Salesforce highlighted as a common data-theft target. After detection, victims received extortion emails threatening publication of stolen data, with some demands signed 'ShinyHunters.'

Okta publicly reports vishing kits targeting SSO accounts

Okta publicly disclosed that custom adversary-in-the-middle phishing kits sold as a service were being used in active attacks against Okta, Microsoft, Google, and cryptocurrency-related accounts. The company described real-time phishing pages synchronized with phone calls to capture credentials and defeat non-phishing-resistant MFA.

Jan 19, 20265mo ago

Okta privately warned customer CISOs about active vishing attacks

Earlier in the week before its public report, Okta privately alerted customer CISOs that attackers were using custom phishing kits in active campaigns to steal Okta SSO credentials and access downstream SaaS applications. The warning described subsequent data theft and extortion risk.

Dec 1, 20257mo ago

Vishing kit activity evolved significantly in late 2025

Okta said the voice-phishing ecosystem and related phishing kits evolved significantly in late 2025, with criminals selling more specialized tooling and even recruiting native English-speaking callers to impersonate IT help desks. This marked a maturation of the social-engineering-as-a-service model.

Apr 1, 20251y ago

Similar vishing/AiTM activity observed by at least April 2025

Reporting indicates comparable voice-phishing and adversary-in-the-middle activity had been observed since at least April 2025, establishing that the tradecraft predated the January 2026 disclosures. The attacks used phone-based social engineering and phishing pages to capture credentials and MFA factors.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

65 LINKEDOpen in app
Affected products
15 linked
OnedriveSharepointSalesforceZendeskMicrosoft OfficeTelegramZoomDropboxDropboxBitwardenKubernetesAsteriskKubernetesGoogle DriveWindows Hello
Organizations
45 linked
Microsoft CorporationOktaGoogleSalesforceZendeskTucowsSlack TechnologiesAtlassianLevelBlueBleepingComputerSalesforceDropboxZoom CommunicationsBoxTelegramCoupa SoftwareXcape IncBinanceLinkedinSnowflakeSuzu LabsSectigoHubspotGeminiFortinetCanvaCoinbaseSnapEpic GamesBroadcomBitwardenYahooVorlonCrypto.comSilent PushRenderFenix24AolAbnormal AIRescanaZoomInfoZoomInfo TechnologiesHoxhuntHadrianSuzu Labs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.