API Security
How a Phone Call Beats MFA: Anatomy of the Wall Street Vishing Wave
Anatomy of the vishing wave hitting Wall Street: how a phone call captures the authenticated session MFA produces, the indicators to hunt for, and the controls that close the exposure.
Amazon's One Medical Confirms a "Limited" Breach. ShinyHunters Claims 8.8 Terabytes and a Deadline. Only One of Those Is Verified.
On June 13, One Medical disclosed unauthorized access to a third-party file storage system holding archived records from its legacy Iora Health and One Medical Seniors patients, describing the scope as a limited subset of files at nine named clinics. Days earlier, on June 18, ShinyHunters posted One Medical to its dark-web leak site, claimed 8.8 terabytes of stolen data, and gave the company until June 22 to begin negotiating before publication. ShinyHunters has released no sample data, so the claim is unverified. This is the same actor, the same playbook, and the same trust gap Cloudskope documented in the Canvas/Instructure breach: a company describing the smallest defensible version of events while a threat actor describes the largest. For boards in healthcare and any regulated-data business, the lesson is not which number to believe. It is to treat both as unproven until the evidence settles it, and to plan for the larger one.
Drift. Gainsight. Now Klue. And This Time, It Wasn't ShinyHunters.
For the third time in ten months, attackers drained Salesforce data through a trusted app. The first two were ShinyHunters. This one wasn’t — and that is why it matters.
.png)