Allure Security learned that the ShinyHunters extortion group used the mckesson[.]claims domain as part of an attack against McKesson employees.
Public source
Publisher name
Public post
"The ShinyHunters extortion group told BleepingComputer that it was behind the attack, claiming it gained access after conducting voice phishing, or vishing, social engi…
Company
Allure Security
End-to-End Managed Digital Brand Protection. We Detect, Disrupt, and Destroy Scams Before Your Customers Ever See Them.
- Industry
- Computer and Network Security
- Location
- Watertown, US
- Company size
- 51–200 employees
About Allure Security
Account Takeover Fraud costs businesses nearly 7 Billion a year. We address the root cause. Our AI catches the scams that other vendors miss by visually examining millions of sites every day to detect online impersonation of your brand. Our solution finds credential theft (phishing), identity theft, payment data theft, personal information theft, and content re-publishing; and responds to mitigate the risk before your customers and your brand become victims. Our unique deception technology takes the fight back to the scammers. We stop them in their tracks by injecting realistic decoy data right into their attack sites. That breaks the scammers’ business model and helps to expose their real identities. Allure also provides best-in-class traditional responses via automated takedowns and blocklisting and a through our seasoned takedown team. Head to our blog for more information about account takeover fraud, cybersecurity trends, and how to protect your customers from the bad guys: https://bit.ly/34fLRae
See moreLatest activity
Latest activity from Allure Security
10 signals
Presence & Recognition
Allure Security examined the RSAC Conference 2026 focus on internal risk and the external implications for brand protection, noting that Mandiant's M-Trends data shows the time between initial access and attacker handoff has collapsed to 22 seconds and 89% of CISOs are accelerating agentic security adoption.
Presence & Recognition
Allure Security hosted a session on September 17 featuring Brett Johnson, a former US Most Wanted cybercriminal who built ShadowCrew, to discuss how criminal operations run at industrial scale.
Research & Knowledge
Allure Security documented 15,000 fake TikTok Shop domains and 10,000 phishing URLs, promoted by AI-generated influencer videos, using CTM360.
Discover more
Similar signals
Similar public activity from other companies.
Products & Services
Blackpoint Cyber
Blackpoint Cyber published a Threat Pulse article detailing a phishing link sent to a spoofed vendor onboarding page that contained an executable using DLL sideloading through a PDF reader to load DonutLoader and Remcos RAT.
Products & Services
Palo Alto Networks Unit 42
Palo Alto Networks Unit 42 announced that the BigBear 2.0 phishing service bypasses multi-factor authentication in a global Microsoft 365 campaign.
Research & Knowledge
Arete
Arete observed Akira, Qilin, and INC Ransom as the top three threat groups in H1 2026, collectively accounting for more than a third of all ransomware and extortion engagements that Arete responded to.
Research & Knowledge
DOT Security
DOT Security published an edition of The DOT Report featuring a confirmed data-extortion breach exposing records from Atlanta, Allstate, Frontier, and Microsoft.
Research & Knowledge
ThreatLight