Bridewell’s BCON Collective has uncovered an active phishing infrastructure spanning more than 100 malicious domains after investigating what initially appeared to be a routine blocked vishing attempt against one of its customers. The investigation found evidence suggesting the campaign is linked to the ShinyHunters cybercriminal group and revealed that the same phishing kit is being shared across multiple Com-affiliated threat actors, highlighting how cybercriminals are collaborating by reusing infrastructure and tooling.
The investigation began when an employee received a fraudulent phone call from someone posing as internal IT support and was directed to a fake Okta single sign-on page. Existing security controls prevented the employee from accessing the malicious website before credentials could be compromised.
Rather than treating the incident as an isolated phishing attempt, Bridewell’s researchers analysed the malicious infrastructure behind the attack. They uncovered more than 100 active phishing domains impersonating trusted identity platforms including Okta and Microsoft Entra ID. The team also linked several domains to organisations that later appeared on the ShinyHunters data leak site, including Abbott, Ralph Lauren and RingCentral, demonstrating how quickly an initial access attempt can escalate into extortion.
According to the research, organisations targeted by related phishing infrastructure appeared on extortion sites between four and 28 days later, with an average timeframe of less than two weeks. Bridewell says this leaves defenders with a narrow window to detect and respond before attackers move from credential theft to wider compromise.
The research found that the phishing infrastructure targeted organisations across financial services, healthcare, technology, retail and professional services, indicating the campaign is not focused on a single industry.
Bridewell is urging organisations to strengthen employee awareness of vishing attacks, implement robust verification procedures for IT support requests, block authentication via unapproved domains, monitor for infrastructure impersonating their organisation and treat failed phishing attempts as valuable intelligence opportunities rather than isolated incidents.
Gavin Knapp, Head of Cyber Threat Intelligence at Bridewell, said: “Blocking one domain or responding to one phishing attempt is only part of the picture. Security teams need to identify the wider infrastructure, understand the tradecraft being reused across campaigns and act quickly. Our research also showed that, in some cases, organisations appeared on extortion sites less than two weeks after related infrastructure became active. That leaves very little time to detect and respond before an initial access attempt becomes a much more serious incident.”
The full research is available here: https://www.bridewell.com/insights/blogs/detail/vishing-call-to-a-shared-com-ecosystem

