Desk live·
ForensicPost
Cloud/Identity/File 25-0813

Attackers Registered Their Own MFA Device After Phishing an SSO Code

In a second variant, operators captured SSO credentials and a one-time code through a branded phishing site, then registered their own MFA device. The stolen code expires; the enrolled device does not.

Constructed geometry · not a chart of case data
TargetEnterprise SSO accounts
ActorShinyHunters
S. Rosler11 min readConfidence: high2 sources reviewed

A second documented variant of the campaign used a victim-branded phishing site: operators called employees, directed them to the site, captured single sign-on credentials and a multi-factor code, and then enrolled an attacker-controlled MFA device on the account.

The Enrolment Is The Whole Point

A captured one-time code is worth one authentication and expires in seconds. Real-time relay phishing has been understood for years, and the mitigation — treat the session as compromised, force reauthentication — is well established.

Registering a new factor converts that momentary access into standing access. The attacker no longer needs the employee, no longer needs to intercept anything, and can authenticate independently whenever they choose.

A password reset does not remove it. Ending the session does not remove it. The account is now legitimately configured to trust a device the organisation does not know about.

Enrolment Is Treated As A Convenience, Not A Control

Adding a device is the operation users perform when they get a new phone. It is designed to be easy, is usually available to any authenticated session, and rarely generates an alert anyone reads.

It is also, functionally, the granting of permanent authentication capability. The corpus records the same asymmetry elsewhere: the operation that establishes durable access is administratively trivial while the operation that removes it requires someone to notice.

The Obvious Control Is Unpopular For Real Reasons

Requiring a second, independent verification before enrolling a factor — or restricting enrolment to managed devices or trusted networks — would close this. It also strands users who genuinely lose a phone while travelling, which produces help-desk calls, which is where the campaign at 25-0806 started.

Every hardening measure here pushes load onto the recovery path, and the recovery path is the softest surface in this database.

How we reported this

Compiled from published vendor threat research, listed below. Attribution follows those assessments. Corrections: corrections@forensicpost.com.

Sources
  1. Threat spotlight: ShinyHunters data breach targets Salesforce amid Scattered Spider collaborationReliaQuest
  2. ShinyHunters threat actor profile: TTPs, IoCs and attacksHuntress
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary