Index live· 1,284 files · 148 editions
ForensicPost

Search the index

6 results
Try
Results for “Vishing”Newest first
26-0714
File

Thirty Million Rows, Claimed. A Limited Number of Systems, Confirmed

Abbott confirmed unauthorised access to a limited number of systems. ShinyHunters claims thirty million rows. Almost everything in between is unestablished.

ShinyHuntersVishing → SSO (claimed)HealthcareIdentity
Sev 4TargetAbbott LaboratoriesActorShinyHuntersUSA
26-0619
File

The Company That Named the Technique Was Also Hit by It

The team that named the cluster was also caught by it, and published. That removes the easiest excuse for ignoring the technique.

UNC6040Vishing → OAuth consentCloudIdentity
Sev 2TargetGoogle (corporate CRM)ActorUNC6040
26-0607
File

UNC6040 Phoned Staff to Authorise Salesforce Connected Apps

A phone call, a consent screen, and a refresh token that outlives every password change. No exploit is involved at any step.

UNC6040Vishing → OAuth consentCloudIdentity
Sev 4TargetSalesforce tenantsActorUNC6040
26-0526
File

Charter Discloses Vishing Breach Affecting 4.9 Million Customer Accounts

A vishing call against an employee’s Entra account, then customer records in a connected CRM. The reported total has moved from 4.9 million upward.

ShinyHuntersVishing → EntraTelecomIdentity
Sev 4TargetCharter CommunicationsActorShinyHunters
22-0524
File

Cisco Breach Began With Corporate Credentials Synced to a Personal Google Account

The browser did nothing wrong. It carried a work password into a personal account, exactly as designed.

YanluowangSynced credentials → vishing → MFA pushTechnologyIdentity
Sev 3TargetCiscoActorYanluowangUSA
ACT-004
Actor

ShinyHunters

Voice phishing into identity providers, then leak-site extortion. Active since 2020.

VishingSSOLeak siteData theft
Profile
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging