
ShinyHunters and the SLSH Supergroup Launch Coordinated Attacks on Enterprise Identity Systems
A highly coordinated identity-focused attack campaign is actively targeting more than 100 major enterprises, including Canva, Atlassian, Epic Games, HubSpot, and Zoom — and it’s bypassing even hardened MFA defenses.
At the center of this activity is ShinyHunters, operating as part of a broader threat alliance known as SLSH — a “supergroup” formed from the combined capabilities of Scattered Spider, LAPSUS$, and ShinyHunters.
This is not automated phishing.
It is human-led, real-time identity compromise — and it’s aimed squarely at Single Sign-On (SSO) platforms, particularly Okta.
🎭 The SLSH Supergroup Explained
Threat intelligence firm Silent Push has identified a surge in infrastructure that mirrors the tactics, techniques, and procedures (TTPs) historically used by SLSH actors.
What makes this campaign especially dangerous is its hybrid approach:
Advanced technical tooling
Highly persuasive voice phishing (vishing)
Live manipulation of authentication flows
Rather than blasting emails at scale, attackers engage victims directly — adapting their approach in real time based on each organization’s login process and MFA configuration.
🔑 How the Attack Works: Live Identity Theft
The campaign centers on a “Live Phishing Panel”, a tool that allows attackers to:
Intercept credentials and MFA tokens in real time
Control phishing pages dynamically during active login sessions
Gain immediate, persistent access to enterprise environments
While one operator manipulates the phishing interface, another may be:
Calling employees
Contacting IT help desks
Posing as internal staff or contractors
This synchronized human interaction allows attackers to defeat MFA methods that rely on user approval — even in mature security environments.
🎯 Who Is Being Targeted
Silent Push has observed active targeting or infrastructure preparation within the last 30 days across multiple sectors:
Technology
Atlassian
Canva
Epic Games
HubSpot
Zoom
Financial Services
Blackstone
RBC
State Street
Healthcare
Biogen
Moderna
Real Estate & Infrastructure
Simon Property Group
Zillow
AECOM
Halliburton
Once an SSO account is compromised, it effectively becomes a skeleton key — unlocking access to cloud apps, internal tools, and sensitive data across the enterprise.
🚨 Attack Progression: From Access to Extortion
Following the LAPSUS$ playbook, the attackers move fast:
Initial SSO compromise via vishing and live phishing
Lateral movement into internal communication platforms (Slack, Microsoft Teams)
Social engineering of administrators to escalate privileges
Rapid data exfiltration
Ransomware deployment and extortion
The goal isn’t persistence — it’s speed and leverage.
🛡️ Why Traditional Defenses Fail
Standard security awareness training alone is insufficient against this threat.
SLSH operators are:
Highly trained in persuasion
Coordinated across multiple attack roles
Adaptive to each victim’s environment
MFA that depends on human approval can be socially engineered. Once an attacker gains SSO access, technical controls often fall too late.
🔐 What Organizations Must Do Now
Elliptic Systems recommends immediate action for organizations at risk:
🚨 Alert employees and help desk staff about active vishing campaigns
🔍 Audit Okta and SSO logs, especially:
“New Device Enrolled” events
Followed immediately by logins from unfamiliar IP addresses
🔐 Transition to phishing-resistant authentication (FIDO2, passkeys)
🌐 Deploy pre-attack intelligence to identify malicious lookalike domains before they go live
Silent Push’s Indicators of Future Attack (IOFA™) demonstrate how DNS-level intelligence can block attacker infrastructure before exploitation begins.
🔎 The Elliptic Systems Perspective
This campaign reinforces a critical reality:
Identity is the new perimeter — and humans are the entry point.
When attackers combine live social engineering with real-time technical control, prevention must begin before credentials are entered.
At Elliptic Systems, we help organizations:
Harden identity and SSO platforms
Simulate vishing attacks against real workflows
Deploy phishing-resistant authentication
Detect attacker infrastructure early — not after compromise
Waiting for a breach notification is no longer an option.
👉 Schedule an Identity Threat Readiness Assessment
⚠️ Final Takeaway
The SLSH supergroup doesn’t break in.
They talk their way in — then move fast.
If a single SSO account can unlock your enterprise,
your identity security must be unphishable by design.
Elliptic Systems — Securing Identity Before Attackers Reach Your People.
