TL;DR: ShinyHunters compromised over 100 organisations in early 2026 by using voice phishing, fake IT support pretexts and real-time MFA interception to obtain legitimate access, according to AuthMind. Authentication success is not identity safety, and post-authentication visibility now matters as much as MFA.
At a glance
What this is: This is an analysis of how ShinyHunters used voice phishing and real-time MFA interception to bypass authentication-only defenses and operate through legitimate SaaS access.
Why it matters: It matters because identity teams need controls that detect what an authenticated user does next, not just whether a login succeeded.
Context
ShinyHunters' 2026 campaign is a reminder that MFA can be bypassed when attackers manipulate the human authentication path rather than the cryptography itself. The governance gap is not whether a login was approved, but whether the organisation can see and constrain what happens after access is granted.
For identity programmes, this is a shift from authentication assurance to post-authentication assurance. The article centres on human IAM and identity observability, but the lesson extends across SaaS access, privileged workflows, and lifecycle governance because legitimate access can still be misused at scale.
The starting position is not atypical. Many enterprises have functioning MFA, conditional access, and awareness training, yet still lack the visibility to distinguish normal logins from malicious use of a valid session.
Key questions
Q: What breaks when attackers use voice phishing to get a legitimate MFA approval?
A: The failure is not the factor itself but the trust assumption behind it. A legitimate MFA approval can still belong to the wrong actor when the user is manipulated in real time. That means authentication logs may look clean while the session is already compromised and ready for post-login abuse.
Q: Why does broad post-login access increase breach impact even with MFA enabled?
A: Because MFA protects the entry point, not the privilege boundary. If an attacker or insider gets a valid session, broad entitlements let them move from a single account compromise to data access, lateral movement and administrative abuse. The size of the breach is set by authorization scope, not login strength alone.
Q: What are the signs that identity observability is failing?
A: You know the control is failing when authentication looks normal but the user suddenly downloads unusual volumes of data, authorizes new apps, or changes MFA settings without rapid detection. The gap is visible only when teams cannot connect login events to the actions that follow them.
Q: How should teams respond when an authenticated session looks compromised?
A: Contain the session first by revoking or invalidating the token, then compare current behaviour against prior access history to determine whether the identity has drifted. Response should focus on limiting further use of the trusted session, because the attacker may already be operating inside the access boundary.
Technical breakdown
Why voice phishing defeats MFA at the session layer
Voice phishing does not break MFA mathematically. It tricks a user into participating in a real authentication flow, often by directing them to a lookalike sign-in page and then capturing the response in real time. Push approvals, one-time codes, and session enrollment prompts can all be replayed if the attacker controls the interaction window. The important distinction is that the identity provider sees a valid challenge and a valid response, so the login appears legitimate. That means the failure occurs above the credential layer and below the user intent layer. Security teams should treat this as a session integrity problem, not just an authentication factor problem.
Practical implication: move beyond factor success metrics and verify whether the session was established through a trusted user path.
Post-authentication identity observability and behavioral baselines
Identity observability is the ability to correlate authentication, application access, privilege changes, and data activity across SaaS and cloud services. Traditional logs tell you who authenticated and when. They rarely explain whether that identity then downloaded unusual volumes of data, authorized a new third-party app, or searched for terms that do not fit historical behavior. Behavioral baselines matter because attacker activity often looks normal in isolation but abnormal in sequence. The control objective is to identify suspicious use of a legitimate session before exfiltration or privilege expansion becomes irreversible.
Practical implication: correlate login events with application and data actions so the post-login chain can be scored as a single identity story.
OAuth authorisations can widen the blast radius after compromise
Once an attacker holds a valid session, the next move is often to persist through additional trust paths such as OAuth consents, mailbox rules, or connected application access. These authorisations can outlive the initial login and create a broader and quieter foothold than the original credential. In the ShinyHunters pattern, the problem is not only stolen access, but the secondary permissioning that turns a single compromised identity into cross-application reach. That is why authentication logs alone miss the real escalation path: the dangerous step is often the delegated trust that follows the login, not the login itself.
Practical implication: inventory third-party app consents and delegated access as part of the same identity control plane as primary authentication.
Threat narrative
Attacker objective: The objective was to obtain legitimate-looking access that could be used to steal data, expand control across cloud services, and delay detection long enough to complete exfiltration.
- Entry began with voice phishing and fake IT support pretexts that directed victims to credential-harvesting pages and real-time MFA interception flows.
- Credential access followed when victims approved the attacker-controlled authentication path and, in some cases, registered attacker devices for multi-factor authentication.
- Escalation and lateral movement occurred as attackers used the valid session to reach SaaS and cloud services, search for sensitive data, and authorize additional access paths.
- Impact came through broad data exfiltration, deletion of security notifications, and prolonged undetected access across multiple organisations.
Breaches seen in the wild
- Uber breach 2022: A contractor's stolen password and MFA fatigue gave a Lapsus$-linked attacker Uber's internal tools; Uber rotated keys to many services.
- Microsoft Midnight Blizzard breach: Midnight Blizzard (APT29) exploited legacy test account without MFA to breach Microsoft.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Authentication success is no longer a reliable security boundary. ShinyHunters shows that a valid login can coexist with malicious intent, which breaks the assumption that identity risk is resolved at the moment MFA succeeds. The practical implication is that identity programmes must measure post-authentication behavior, not treat it as an optional enhancement.
Identity observability is now a control plane requirement, not a monitoring luxury. When attackers operate through legitimate sessions, the only durable detection point is the sequence of actions that follows authentication across SaaS, cloud, and collaboration services. Organisations that still rely on single-product audit logs are leaving the real attack chain ungoverned.
Post-authentication abuse creates identity blast radius faster than traditional IAM reviews can react. The named concept here is identity blast radius, the amount of data and application reach a compromised session can touch before containment. ShinyHunters used normal-looking access to move across records, documents, and notifications, which means access review cycles alone are too slow to matter once a session is active.
MFA-only strategies create false comfort when human-mediated fraud is the entry point. The control was designed for credential assurance, not for adversary-in-the-loop social engineering that turns the user into part of the attack path. The implication is that human IAM, privileged access, and SaaS governance must be analysed together rather than as separate controls.
Lifecycle governance must now include delegated trust paths and device enrollment outcomes. If a compromised session can register an attacker-controlled MFA device or authorize a new application, offboarding and recertification logic must account for those secondary objects, not just the user account. Practitioners should treat those trust extensions as part of the identity record, because that is where the persistence lives.
What this signals
Identity blast radius now matters more than login success. Security programmes that stop at authentication leave the real risk untouched, because the attacker’s useful work begins after the session is approved. Practitioners should map which SaaS applications, delegated consents, and notification channels can be abused inside a valid session, then treat those paths as part of the identity control plane.
Human-mediated fraud and machine-enforced controls have become the same problem. A user who is tricked into approving access can create a compromise that looks indistinguishable from routine access unless behaviour is analysed in context. That is why post-authentication detection belongs alongside IAM, not underneath it.
Session-centric governance is becoming the minimum viable posture for identity teams. Access reviews and periodic recertification still matter, but they do not catch abuse that unfolds inside a single authenticated session. The practical shift is to govern the issuance, use, and extension of access as one continuous lifecycle, not as separate checkpoints.
For practitioners
- Strengthen phishing-resistant authentication Prioritise FIDO2 security keys or passkeys for workforce access where vishing and real-time phishing are credible threats. Keep push-based MFA and one-time codes only where the risk is understood and compensating monitoring is in place.
- Build post-authentication detection paths Correlate logins with downstream actions such as file downloads, OAuth consents, privilege changes, and mailbox rule creation across SaaS services. The goal is to detect session abuse while the attacker is still inside the environment.
- Review delegated access and third-party app consents Inventory the applications and services that can extend a user session beyond the original login. Remove unused consents, restrict high-risk scopes, and treat delegated access as part of identity governance.
- Hunt for anomalous MFA device enrollment Flag new MFA device registrations, notification suppression, and security-method changes as high-signal events, especially when they are followed by data access that does not match the user baseline.
- Align response playbooks to authenticated abuse Assume some incidents will begin with a valid login rather than a failed one, and define containment steps for active sessions, token revocation, and trust-path shutdown before exfiltration completes.
Key takeaways
- ShinyHunters demonstrates that MFA can be socially engineered without being technically broken, which leaves organisations exposed when they treat login success as proof of user trustworthiness.
- The breach pattern scaled across many organisations because attackers operated through valid sessions, delegated trust paths, and normal-looking SaaS activity rather than obvious malware or exploit chains.
- The control gap is post-authentication visibility. Teams need to detect unusual behaviour, revoke suspicious trust extensions, and contain active sessions before data exfiltration completes.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | MFA interception and adversary-in-the-loop approval were central to the compromise. |
| NHI-10 — Human Use of NHI | The attacker exploited the user as part of the authentication process. | |
| Recommendation — Harden authentication paths against real-time phishing and approval fraud. Remove user-driven trust decisions from sensitive identity enrollment and approval flows. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article focuses on post-login abuse of valid entitlements and delegated access. |
| DE.CM-09 — Network and Cybersecurity Event Detection | Detection depends on correlating login events with downstream behavior across services. | |
| Recommendation — Continuously review entitlements and delegated access after authentication. Correlate identity and application telemetry to detect suspicious post-authentication behavior. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The campaign used credential harvesting and movement across SaaS applications. |
| Recommendation — Track credential access and lateral movement patterns across identity-managed environments. | ||
Key terms
- Identity Observability: Identity observability is a continuous governance approach that correlates identity activity with business context, telemetry, and policy state. Instead of checking access at a single point in time, it tracks what an identity can do, what it did, and why that action matters to the business.
- Session abuse: Session abuse is the misuse of an already established browser session to perform actions that were not intended by the legitimate user or system owner. It can include token theft, consent misuse, hijacked navigation, or post-authentication actions that bypass the original access decision.
- Delegated Trust Path: A route into an environment created by an already-approved relationship such as OAuth, service account delegation, or API connectivity. These paths are attractive to attackers because they often inherit trust from the original configuration and can bypass direct user interaction.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
Deepen your knowledge
Identity lifecycle management, secrets management, and workload identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org