The ShinyHunters extortion group claimed responsibility for a recent Okta SSO voice-phishing (vishing) campaign used to steal authentication codes and access victim environments. The group told reporters and researchers it used vishing to obtain Okta single-sign-on codes to compromise Crunchbase and Betterment, and then published alleged stolen data after the organizations reportedly rejected extortion demands; ShinyHunters also said additional victims exist and that more disclosures are forthcoming.
ShinyHunters published alleged datasets for Crunchbase, Betterment, and SoundCloud on a newly launched leak site, asserting the dumps contain PII and large record counts (reported as >20 million for Betterment, ~2 million for Crunchbase, and ~30+ million for SoundCloud). SoundCloud stated it is aware of data published online allegedly taken from its organization and said its security team, supported by third-party experts, is reviewing the claim and the posted data; ShinyHunters asserted SoundCloud access was not obtained via SoundCloud’s Okta credentials. SoundCloud had previously confirmed a breach affecting roughly 20% of users (about 28 million based on public user counts), while Crunchbase and Betterment had not publicly responded at the time of reporting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Researchers and journalists reported that the campaign was 'ShinyHunters-branded' but warned the name could reflect misattribution or opportunistic reuse rather than confirmed actor identity. They advised focusing on the observed tactics, techniques, and procedures instead of branding alone.
Silent Push assessed that more than 100 Okta SSO accounts at high-value enterprises had been targeted or had attack infrastructure prepared against them, while cautioning this did not prove all named companies were breached. Mandiant corroborated the ongoing campaign and described post-compromise SaaS data theft and extortion activity.
ShinyHunters told reporters it used voice-phished Okta SSO codes to access Crunchbase and Betterment. Downloaded Crunchbase files were reported to contain personally identifiable information and corporate documents.
Hudson Rock co-founder Alon Gal said ShinyHunters confirmed to him that it was behind the recent Okta-focused vishing campaign. He also reported that the group had published alleged data from Crunchbase, SoundCloud, and Betterment on its new leak site.
ShinyHunters opened a new Tor-based victims blog to publish stolen data and pressure victims who refused extortion demands. The site listed alleged victims including Crunchbase, SoundCloud, and Betterment.
Okta Threat Intelligence issued an alert warning that criminals were using voice-phishing kits to target Google, Microsoft, and Okta accounts. Okta and other researchers emphasized the activity relied on social engineering rather than an Okta product vulnerability.
An active campaign used phone-based social engineering to steal SSO credentials and MFA codes for Okta, Microsoft, and Google-linked accounts, then pivot into SaaS environments for data theft and extortion. Researchers later said the operation also enrolled attacker-controlled devices into victims' MFA solutions.
Sophos identified a cluster of roughly 150 malicious domains impersonating SSO and authentication providers that began appearing in December 2025. The infrastructure suggested broad preparation for voice-phishing and credential-theft operations against enterprise identity platforms.
SoundCloud previously confirmed a breach in December 2025. Later reporting said the company was reviewing ShinyHunters' claim that data from SoundCloud had been published on the group's new leak site.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
cyberscoop.com
Open sourcego.theregister.com
Open sourcedatabreaches.net
Open sourcego.theregister.com
Open sourcedatabreaches.net
Open sourcelinkedin.com
Open sourcelinkedin.com
Open sourcelinkedin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.