Social Engineering Attacks Bypass MFA, Mandiant Warns of Evolving Vishing Campaigns
Social engineering attacks are becoming increasingly sophisticated, with a notable shift towards bypassing multi-factor authentication (MFA) through advanced vishing campaigns. Cybersecurity firm Mandiant has identified an active vishing campaign, linked to the ShinyHunters criminal syndicate, that is successfully harvesting MFA codes to infiltrate SaaS platforms. These attacks, tracked under UNC6661, UNC6671, and UNC6240, demonstrate that human manipulation can circumvent even widely deployed security controls like Single Sign-On (SSO) and MFA. The attackers impersonate IT support staff, guiding victims to counterfeit SSO portals and relaying credentials in real-time. This method exploits the inherent trust between employees and internal support teams, making it uniquely effective against modern MFA deployments. Phishing remains the most prevalent social engineering technique, accounting for 77.8% of such attacks, highlighting the continued reliance on human vulnerability.