{"id":17345,"date":"2026-08-02T15:49:05","date_gmt":"2026-08-02T15:49:05","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17345"},"modified":"2026-08-02T15:49:05","modified_gmt":"2026-08-02T15:49:05","slug":"bcon-collective-shinyhunters-it-safety-guru","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17345","title":{"rendered":"BCON Collective ShinyHunters &#8211; IT Safety Guru"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"107\" data-end=\"635\">Bridewell\u2019s <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.itsecurityguru.org\/2026\/07\/22\/bridewell-launches-dedicated-threat-intelligence-practice-bcon-collective\/\">BCON Collective<\/a> has uncovered an lively phishing infrastructure spanning greater than 100 malicious domains after investigating what initially gave the impression to be a routine blocked vishing try towards certainly one of its clients. The investigation discovered proof suggesting the marketing campaign is linked to the ShinyHunters cybercriminal group and revealed that the identical phishing equipment is being shared throughout a number of Com-affiliated menace actors, highlighting how cybercriminals are collaborating by reusing infrastructure and tooling.<\/p>\n<div class=\"jeg_ad jeg_ad_article jnews_content_inline_ads  \">\n<div class=\"ads-wrapper align-right \"><a rel=\"nofollow\" target=\"_blank\" href=\"http:\/\/bit.ly\/jnewsio\" aria-label=\"Visit advertisement link\" target=\"_blank\" rel=\"nofollow noopener\" class=\"adlink ads_image align-right\"><br \/>\n                                    <img decoding=\"async\" class=\"lazyload\" src=\"https:\/\/itsecguru.dessol.com\/wp-content\/uploads\/2018\/08\/ad_300x250.jpg\" alt=\"\" data-pin-no-hover=\"true\"\/><br \/>\n                                <\/a><\/div>\n<\/div>\n<p data-start=\"637\" data-end=\"934\">The investigation started when an worker acquired a fraudulent cellphone name from somebody posing as inner IT assist and was directed to a faux Okta single sign-on web page. Current safety controls prevented the worker from accessing the malicious web site earlier than credentials could possibly be compromised.<\/p>\n<p data-start=\"936\" data-end=\"1455\">Moderately than treating the incident as an remoted phishing try, Bridewell\u2019s researchers analysed the malicious infrastructure behind the assault. They uncovered greater than 100 lively phishing domains impersonating trusted identification platforms together with Okta and Microsoft Entra ID. The group additionally linked a number of domains to organisations that later appeared on the ShinyHunters information leak web site, together with Abbott, Ralph Lauren and RingCentral, demonstrating how rapidly an preliminary entry try can escalate into extortion.<\/p>\n<p data-start=\"1457\" data-end=\"1796\">In response to the analysis, organisations focused by associated phishing infrastructure appeared on extortion websites between 4 and 28 days later, with a mean timeframe of lower than two weeks. Bridewell says this leaves defenders with a slender window to detect and reply earlier than attackers transfer from credential theft to wider compromise.<\/p>\n<p data-start=\"1798\" data-end=\"2018\">The analysis discovered that the phishing infrastructure focused organisations throughout monetary providers, healthcare, know-how, retail {and professional} providers, indicating the marketing campaign will not be targeted on a single trade.<\/p>\n<p data-start=\"2020\" data-end=\"2383\">Bridewell is urging organisations to strengthen worker consciousness of vishing assaults, implement sturdy verification procedures for IT assist requests, block authentication through unapproved domains, monitor for infrastructure impersonating their organisation and deal with failed phishing makes an attempt as invaluable intelligence alternatives fairly than remoted incidents.<\/p>\n<p data-start=\"2385\" data-end=\"2859\" data-is-last-node=\"\" data-is-only-node=\"\">Gavin Knapp, Head of Cyber Risk Intelligence at Bridewell, mentioned: \u201cBlocking one area or responding to 1 phishing try is barely a part of the image. Safety groups have to establish the broader infrastructure, perceive the tradecraft being reused throughout campaigns and act rapidly. Our analysis additionally confirmed that, in some circumstances, organisations appeared on extortion websites lower than two weeks after associated infrastructure turned lively. That leaves little or no time to detect and reply earlier than an preliminary entry try turns into a way more severe incident.\u201d<\/p>\n<p data-start=\"2385\" data-end=\"2859\" data-is-last-node=\"\" data-is-only-node=\"\">The total analysis is offered right here: https:\/\/www.bridewell.com\/insights\/blogs\/element\/vishing-call-to-a-shared-com-ecosystem<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Bridewell\u2019s BCON Collective has uncovered an lively phishing infrastructure spanning greater than 100 malicious domains after investigating what initially gave the impression to be a routine blocked vishing try towards certainly one of its clients. The investigation discovered proof suggesting the marketing campaign is linked to the ShinyHunters cybercriminal group and revealed that the identical [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17347,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[10009,2277,6284,211,5450],"class_list":["post-17345","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-bcon","tag-collective","tag-guru","tag-security","tag-shinyhunters"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17345","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17345"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17345\/revisions"}],"predecessor-version":[{"id":17346,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17345\/revisions\/17346"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17347"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17345"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17345"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17345"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-02 17:46:42 UTC -->