Abbott confirmed unauthorised access to a limited number of systems. ShinyHunters claims thirty million rows. Almost everything in between is unestablished.
The team that named the cluster was also caught by it, and published. That removes the easiest excuse for ignoring the technique.
A phone call, a consent screen, and a refresh token that outlives every password change. No exploit is involved at any step.
A vishing call against an employee’s Entra account, then customer records in a connected CRM. The reported total has moved from 4.9 million upward.
The browser did nothing wrong. It carried a work password into a personal account, exactly as designed.
Voice phishing into identity providers, then leak-site extortion. Active since 2020.