Bridewell’s BCON Collective uncovers shared phishing infrastructure linked to ShinyHunters after blocked vishing attack banner image
News

Bridewell’s BCON Collective uncovers shared phishing infrastructure linked to ShinyHunters after blocked vishing attack

31 July 2026
Single fraudulent IT support call leads investigators to identify more than 100 malicious domains used across a shared criminal phishing ecosystem.

BCON Collective, Bridewell's specialist cyber threat intelligence and research practice, has uncovered evidence of an active phishing infrastructure spanning more than 100 malicious domains after investigating a blocked vishing attack against one of its customers. The investigation indicates the incident is most likely attributable to ShinyHunters, while also revealing that the same phishing kit appears to be shared across multiple Com-affiliated cybercriminal groups, demonstrating how attackers are collaborating by reusing common infrastructure and tooling.

The investigation began after an employee received an unsolicited phone call on their personal mobile from an individual posing as IT support. The caller claimed an internal service ticket required urgent attention and attempted to direct the employee to a fraudulent Okta single sign-on portal. Existing security controls prevented access to the malicious website before any credentials could be entered.

Rather than dismissing the incident as a failed phishing attempt, the BCON Collective team analysed the underlying infrastructure. Using technical indicators recovered from the blocked domain, researchers uncovered a wider campaign spanning more than 100 operational domains, all using variants of the same phishing kit to impersonate trusted identity providers including Okta and Microsoft Entra ID.

While the infrastructure appears to be shared across several documented threat clusters, the strongest evidence points to ShinyHunters in this incident. Researchers also linked domains identified during the investigation to organisations later named on the ShinyHunters data leak site, including Abbott, Ralph Lauren and RingCentral, illustrating how rapidly an initial compromise can progress to extortion.

The research also highlights the speed at which organisations may move from being targeted to appearing on a ransomware or extortion leak site. Across the confirmed cases analysed, the time between related domain activity and public victim listing ranged from four to 28 days, with an average of less than two weeks.

Organisations urged to take notice

Organisations that rely heavily on cloud identity platforms and service desk workflows, particularly those operating critical services or holding sensitive customer data, should take note of the findings. The infrastructure identified during the investigation targeted organisations across financial services, healthcare, technology, retail and professional services, demonstrating that the campaign is not confined to a single sector.

How organisations can reduce the risk

Bridewell recommends organisations:

  • Train employees to recognise and report vishing attempts.
  • Establish clear procedures for verifying requests from internal IT teams.
  • Prevent users from authenticating through unapproved or lookalike domains.
  • Monitor for suspicious infrastructure impersonating their organisation.
  • Treat failed phishing attempts as intelligence opportunities that may reveal wider campaigns.

"What makes this research significant is that it started with a single phone call that, on the surface, appeared to have been stopped before any damage was done,” said Gavin Knapp, Head of Cyber Threat Intelligence at Bridewell. “By looking beyond the individual incident, we uncovered an active phishing ecosystem spanning more than 100 domains that appears to be shared across multiple criminal groups.

"That changes how defenders should think about these attacks. Blocking one domain or responding to one phishing attempt is only part of the picture. Security teams need to identify the wider infrastructure, understand the tradecraft being reused across campaigns and act quickly. Our research also showed that, in some cases, organisations appeared on extortion sites less than two weeks after related infrastructure became active. That leaves very little time to detect and respond before an initial access attempt becomes a much more serious incident."

BCON Collective brings together Bridewell's intelligence-led services, original threat research and expert analysts under a dedicated cyber threat intelligence practice. The team delivers strategic, operational and tactical intelligence to help organisations identify and respond to emerging threats before they become incidents.


The full research report, including indicators of compromise, is available here: https://www.bridewell.com/insights/blogs/detail/vishing-call-to-a-shared-com-ecosystem