Vishing + Phishing Drive Major Data Theft Claims

Check Point Research · Medium sophistication
Last updated September 1, 2026

This weekly threat bulletin highlights multiple real-world incidents, including a healthcare data breach claim where attackers reportedly used phone-based social engineering (vishing) to compromise identity accounts and access cloud apps. It also describes a large-scale “debt relief” email phishing campaign designed to trick recipients into calling attacker-controlled phone numbers, where the scammers then attempted to harvest personal and financial data.

How the attack worked

This breakdown covers two related social engineering patterns described in a recent threat bulletin. In the first, a large-scale phishing campaign used fraudulent debt-relief emails to push recipients toward calling attacker-controlled phone numbers. Once a victim called, the conversation itself became the attack surface: scammers used the call to collect personal and financial information under the guise of helping with debt relief.

In the second pattern, a threat group claimed it used vishing, phone-based social engineering, to compromise Okta identity accounts. Because Okta functions as a single sign-on layer, compromising those accounts gave attackers a path into connected cloud applications such as Salesforce and Snowflake.

Why it succeeded

Both scenarios work by moving the interaction away from email, where security tools and skepticism are strongest, and into a live phone call, where pressure and trust can be manipulated in real time. The debt-relief pretext relies on a plausible, emotionally relevant topic to get the recipient to make the first move. The Okta-related vishing relies on the caller appearing to be legitimate support, asking the target to verify identity or approve a login prompt in a way that feels routine.

Identity systems make this especially risky. A single compromised SSO account can expose multiple connected tools at once, which is why the reported access reportedly extended beyond the initial account into Salesforce and Snowflake.

What to watch for

  • An unexpected email urging the recipient to call a phone number, especially around financial or debt-related topics
  • Any phone call requesting login credentials, one-time passcodes, or approval of an authentication prompt
  • Pressure to act immediately or bypass normal verification steps
  • Requests for personal or financial details during an unsolicited call

Building resistance

Organizations can reduce exposure by training staff to treat unsolicited "call this number" messages as high-risk and to verify such requests through a separately confirmed, trusted channel rather than the number provided in the message. Staff should also be trained to never share MFA codes or approve unexpected login prompts during a phone call, regardless of how confident or official the caller sounds.

Because identity accounts can unlock access to multiple SaaS platforms, limiting what any single account can reach, and applying strong verification steps for helpdesk-style requests, helps contain the impact if a vishing attempt does succeed. Awareness training that specifically covers phone-based pretexts, not just email phishing, is a key part of closing this gap, and can incorporate the MITRE technique referenced for phishing for information (https://attack.mitre.org/techniques/T1598/).

Key findings

  • McKesson disclosed a breach tied to unauthorized access to third-party applications; a threat group claimed it used vishing to compromise Okta accounts and access Salesforce and Snowflake.
  • Check Point reported a large-scale “debt-relief” email phishing campaign that pushed recipients to call attacker-controlled phone numbers; calls were used to collect personal and financial information.
  • The bulletin also notes an AI-enabled phishing-as-a-service operation (AnonyMousKIT) using multi-channel outreach (email, text, WhatsApp, and AI voice calls) to steal Apple IDs, passcodes, and 2FA codes.

Who’s being targeted

  • Commonly targeted roles: All employees, IT/Helpdesk, Finance, HR, Sales/CRM users, Employees with access to sensitive cloud data (data/analytics teams).
  • Affected industries: Healthcare and pharmaceutical distribution, Air transportation/airport services, Government, Medical devices/manufacturing, Cross-industry (phishing campaigns targeting many organizations).
  • Attack channels: email, vishing.
  • Impersonated: Debt relief service (fraudulent), Identity provider support / internal IT (implied via Okta account compromise).

Red flags to watch for

  • Unexpected debt-relief message sent to a work address
  • Push to move the conversation off email onto a phone call
  • Request for sensitive personal or financial information
  • Unsolicited call about account issues
  • Requests to approve logins or share one-time codes
  • Pressure/urgency to act immediately
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is a call-back phishing scam?

It is an email, such as a fake debt-relief message, that pushes the recipient to call a phone number rather than click a link. Once on the phone, the attacker uses social engineering to collect personal and financial information.

How did vishing lead to cloud data exposure in this report?

A threat group claimed it used vishing to compromise Okta identity accounts, which were then used to reach connected apps like Salesforce and Snowflake.

Why is voice-based social engineering effective?

Callers can sound like legitimate support staff, create urgency, and ask targets to approve login prompts or share one-time codes in the moment, which bypasses many email-based defenses.

What should employees do if they get an unsolicited call about an account issue?

They should not share credentials or approve login prompts on the call, and should instead verify the request through a known, trusted internal channel before taking action.

Read the video transcript

Imagine this: a phone call helps steal 284 million patient records… and it starts with a single email. McKesson reported attackers used vishing to get into Okta, then into Salesforce and Snowflake. Another campaign sent fake debt‑relief emails just to make people call attacker‑controlled phone numbers. Here’s the trick: the email feels helpful, “call us for debt relief.” The call feels legit, “IT from Okta support, can you verify a code?” But they’re just moving you off email to a phone call to grab your login and MFA. Your move: if an email or caller tells you to share a code or approve a login, hang up and contact IT using our official helpdesk channel, never the phone number or link they gave you.

Similar attacks

Vishing Led to Okta Takeover at McKesson

Vishing Led to Okta Takeover at McKesson

McKesson disclosed a breach tied to unauthorized access of third-party applications and data theft affecting some customers. The ShinyHunters extortion group claims it used phone-based social engineering (vishing) to steal employee credentials, took over Okta single sign-on accounts, and then…

August 31, 2026
Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
ShinyHunters Vished McKesson Staff, Claims 284M Records

ShinyHunters Vished McKesson Staff, Claims 284M Records

Boston Scientific and McKesson disclosed separate cyber incidents impacting healthcare operations and sensitive data. Boston Scientific’s ongoing attack disrupted remote monitoring for some implanted cardiac devices, while McKesson confirmed unauthorized access to third-party apps tied to specific…

August 31, 2026
ReliaQuest Employee Tricked Into Okta SSO Login

ReliaQuest Employee Tricked Into Okta SSO Login

ReliaQuest confirmed an employee was socially engineered into entering their password on a fake SSO page and approving an MFA push, giving attackers a brief “view only” session in the company’s identity dashboard. The attackers allegedly impersonated a named member of the security team over the…

August 25, 2026
“Work Panel” Streamlines Vishing Into One Console

“Work Panel” Streamlines Vishing Into One Console

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites and guide victims through password and MFA capture. The tool clones brand look-and-feel for services like Okta and Microsoft 365, then lets a…

July 29, 2026
Vishing Console + Fake CCleaner Trap Users

Vishing Console + Fake CCleaner Trap Users

This bulletin highlights multiple real-world threats, including voice-phishing (vishing) operations that industrialize account takeovers and a fake CCleaner download site that installs spyware. The items provide concrete, repeatable lures (a vishing-driven takeover workflow and a lookalike software…

August 17, 2026