TL;DR: Scattered Lapsus$ Hunters are combining vishing with adversary-in-the-middle phishing to steal SSO credentials, MFA codes, and live sessions from hundreds of organisations across Okta, Entra, and Google, according to Push Security. The attack works because identity-first compromise bypasses endpoint and network controls and turns SSO into the blast-radius multiplier.
At a glance
What this is: Scattered Lapsus$ Hunters are pairing voice phishing with adversary-in-the-middle phishing to compromise SSO accounts, capture live sessions and move quickly into downstream apps for theft and extortion.
Why it matters: IAM, IGA and PAM teams need to treat SSO as a high-value blast-radius multiplier, because identity-first attacks can bypass traditional perimeter controls and leave little for incident response to clean up.
Context
Hybrid vishing and adversary-in-the-middle phishing target the identity layer rather than the endpoint, which is why conventional detection models miss so much of the activity. In this campaign, the attacker impersonates IT support, steers the victim into a crafted login flow and captures credentials, MFA codes and live session access across SSO platforms.
For identity governance teams, the important shift is not just that credentials are stolen. It is that the attacker inherits the user’s downstream access graph through SSO, which makes the compromise broader than a single account and harder than a normal password reset problem to unwind.
Key questions
Q: What breaks when vishing is combined with AiTM phishing against SSO accounts?
A: The failure is the assumption that authentication happens in a trusted, static channel. When voice social engineering and AiTM phishing are combined, the attacker can steer the victim through login, MFA and session capture in real time, bypassing controls that expect a user to authenticate once and remain safe.
Q: Why do SSO compromises create such broad downstream risk?
A: Because the primary login becomes a control plane for many connected applications. Once an attacker owns the SSO session, they can enumerate access, reach multiple SaaS platforms and sometimes add new persistence methods, which turns one identity compromise into a much wider recovery problem.
Q: What are the signs that an identity provider account has been abused through phishing?
A: Look for unusual MFA enrolment changes, unexpected passkey creation, logins from uncharacteristic browser or device combinations, and new sessions followed by rapid access to multiple SaaS applications. Those signals often show the account was captured through live phishing rather than a simple password leak.
Q: Should organisations prioritise passkeys over browser-based detection for SSO protection?
A: No single control is enough on its own. Passkeys reduce phishing success, but browser-based detection helps catch live AiTM pages and operator-led attacks that still get a user to interact. The strongest posture combines phishing-resistant authentication, browser-level inspection and tight recovery governance.
Technical breakdown
How operator-led AiTM phishing captures live SSO sessions
AiTM, or adversary-in-the-middle, phishing sits between the user and the legitimate identity provider. The victim enters credentials and completes MFA on a lookalike page, but the attacker relays the session in real time and can harvest tokens, cookies or other session artefacts. That means the compromise is not limited to a password or one-time code. In SSO environments, the resulting session often inherits access to multiple SaaS applications, so the attacker does not need to repeat the phishing step for each target. The real value is session continuity, not just credential theft.
Practical implication: Treat live session capture as a separate control problem from password theft and do not rely on MFA alone as the stopping point.
Why hybrid vishing changes the authentication threat model
Vishing adds a human operator who can adapt the script while the victim is still on the call. That changes the attack from static phishing to guided authentication abuse, where the attacker can coach the user through passkey setup, MFA prompts or recovery steps in real time. Because the delivery vector is a phone call rather than email, the usual mail gateway and URL reputation controls do not see the whole attack path. This is one reason the campaign can keep changing shape while still reaching the same outcome: identity compromise at the SSO layer.
Practical implication: Extend identity monitoring and help-desk verification controls beyond email, because the initial lure now arrives through voice rather than a mailbox.
How SSO becomes the control plane after compromise
Once the attacker has access to the SSO dashboard, they can enumerate connected applications, test which services are reachable and then pursue data theft or persistence. That is the structural risk of federated identity: compromise one primary login and you may inherit many dependent apps, each with its own value and recovery burden. The article’s mention of ghost logins and backdoor methods shows why cleanup is difficult. A session or added login method can survive the original user’s awareness long enough to extend dwell time, complicate response and increase extortion leverage.
Practical implication: Assume compromised SSO can create downstream persistence and prioritise revocation paths that remove sessions, enrolments and secondary access methods together.
Threat narrative
Attacker objective: The attacker wants durable access to SSO-linked applications so they can steal data, maintain footholds and extort the victim organisation.
- Entry begins with voice phishing, where an attacker impersonates internal IT support and persuades the target to visit a malicious login site.
- Credential access occurs when the AiTM page captures SSO credentials, MFA codes and live session material during the authentication flow.
- Escalation follows as the attacker uses the stolen SSO session to inspect accessible platforms and broaden their reach across connected services.
- Impact is data theft and extortion, with the compromise potentially leaving backdoor access methods that make cleanup and recovery harder.
Breaches seen in the wild
- Okta support system breach 2023: A support service account credential saved in a personal Google profile let attackers take HAR files and hijack five Okta customers' sessions.
- Salesloft OAuth token breach: hackers stole OAuth tokens to access Salesforce data via Salesloft.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
SSO compromise has become an access multiplier, not a login event: Once an attacker reaches the identity provider, the real target is the downstream application graph. The article shows why federated access concentrates risk into a single session boundary that was never designed to carry this much trust. For practitioners, SSO must be governed as a high-blast-radius control plane, not just an authentication convenience.
Identity-first attacks now outrun endpoint-centric detection: Hybrid vishing plus AiTM phishing avoids the surfaces that many security stacks watch most closely. Mail filters, endpoint tools and network indicators miss much of the live interaction because the compromise is negotiated in the browser and on the phone. The implication is that detection logic must move to session behaviour, user interaction and browser-level telemetry.
Phishing-resistant authentication is necessary but not sufficient when support workflows can be socially engineered: The campaign shows that passkey adoption, MFA enrolment and recovery journeys can all be turned into attack paths if the human operator is manipulated at the same time. The control gap is not only weak authentication, but trust placed in identity support interactions that are still easy to impersonate. Practitioners need to reassess where user assistance becomes an attack surface.
Browser-mediated identity checks are becoming part of the defence stack: The article points to a market shift toward in-session detection because static indicators are too easy to evade. That does not replace identity governance, but it does change where enforcement can happen in real time. For security teams, the practical lesson is that login-time controls and runtime verification need to work together.
Hybrid vishing plus AiTM phishing creates a post-compromise cleanup problem as much as an access problem: The combination of live session theft and attacker-controlled post-login actions can leave behind enrolments, backdoors and ghost logins that outlive the original compromise. That makes identity recovery a lifecycle issue, not just an incident-response task. The better framing is identity persistence after compromise, because that is what keeps the intrusion alive.
From our research library:
- Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.
What this signals
Identity compromise now behaves like infrastructure compromise: once an attacker controls the SSO session, they can move across the user’s authorised application set without touching the network perimeter. That shifts the security conversation from account protection to access graph containment.
Help-desk and recovery paths have become a parallel attack surface: the campaign works because human support workflows can be manipulated into confirming or resetting access. Identity programmes need to treat recovery, enrolment and verification flows as first-class controls, not administrative chores.
Live phishing is forcing more in-browser enforcement: static indicators are losing value when the attacker can change the page in real time during the call. The practical response is to detect session behaviour where the compromise actually occurs, not where legacy tools expect it.
For practitioners
- Harden SSO recovery and help-desk verification Require out-of-band identity verification for password resets, MFA changes and passkey enrolment so voice-based impersonation cannot drive account takeover.
- Detect live session theft in the browser Use browser telemetry to flag cloned login pages, suspicious login flows and real-time MFA relay behaviour before the session is established.
- Review downstream application exposure Map which SaaS platforms inherit access from each primary SSO identity so a single compromised login can be contained quickly.
- Remove persistence paths after identity compromise Revoke sessions, passkey enrolments and any newly added recovery methods together, because cleaning only the password leaves other footholds intact.
Key takeaways
- Hybrid vishing plus AiTM phishing turns SSO into a broad access gateway, so one compromised login can expose multiple connected services at once.
- The campaign succeeds because live session capture and support workflow manipulation defeat controls that were designed for static credential theft.
- Organisations need recovery governance, phishing-resistant authentication and browser-level detection to reduce the blast radius of identity-first compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The campaign abuses authentication flows with AiTM phishing and session theft. |
| NHI-10 — Human Use of NHI | Victims are socially engineered into using identity flows in ways the attacker controls. | |
| NHI-05 — Overprivileged NHI | Stolen SSO sessions inherit broad downstream access, amplifying the impact of compromise. | |
| Recommendation — Map phishing-resistant login requirements to NHI-04 and reduce reliance on reusable session-bound credentials. Review where humans can be tricked into operating NHI controls and add verification gates to those steps. Shrink inherited access scopes and segment SSO-linked privileges so one session does not expose many apps. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about how identity compromise expands entitlements through SSO. |
| Recommendation — Revalidate access permissions and entitlements for SSO-linked accounts after suspicious authentication events. | ||
| MITRE ATT&CK | TA0006; TA0008 — Credential Access; Lateral Movement | The attack chain steals credentials and then moves across connected services. |
| Recommendation — Correlate credential theft with follow-on lateral movement across SaaS platforms and prioritise containment. | ||
Key terms
- Adversary-in-the-middle phishing: A phishing method that places an attacker between the user and the real identity provider so the attacker can intercept or relay the authenticated session. It often preserves the user experience, which is why it can evade awareness and some detection paths while still producing usable session tokens.
- Hybrid vishing: A social engineering pattern that combines voice impersonation with another attack channel, usually a phishing page or login relay. The call is used to build trust and steer the victim through the authentication steps the attacker needs, making the compromise harder to spot with email-centric controls.
- SSO session hijacking: The takeover of a federated login session after the identity provider authenticates the user. The attacker gains the user’s active access path into connected applications, which can make one compromised session more damaging than a single stolen password.
- Identity Recovery: Identity recovery is the process of restoring identity systems to a trusted state after compromise. It includes containment, forensic validation, removal of persistence, and confirmation that access controls and directory relationships no longer expose the environment.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org