Skip to content

🇫🇷 ShinyHunters

Threat-actor battle card · maintained from public sources · last updated 2026-08-22 · also known as ShinyCorp

CategoryData-theft extortion
AttributionDecentralized criminal group; French nationals identified and prosecuted (DOJ, Western District of Washington, June 2021 indictment); Mandiant tracks as UNC6240 (primary extortion ops), UNC6661 (vishing/credential harvesting), UNC6671 (unbranded extortion/potential affiliate activity); no confirmed nation-state sponsorship
First seen2020-01
StatusActive
Victims YTD55+
Primary targetsEducation, Government, Intergovernmental organisations, Hospitality, Entertainment, Travel, Technology, Healthcare

Overview

ShinyHunters is a prolific data-theft extortion group active since early 2020, operating a pure extortion model without file encryption: steal data, set a countdown deadline, and publish if payment is refused. Since 2019 (formation) through mid-2026, the group has claimed 40+ breaches in 2026 alone and an estimated 1.8+ billion records across all operations. The group is decentralized — multiple individuals operate under the ShinyHunters brand, enabling it to survive arrests, infrastructure seizures, and operator turnover. Mandiant (Google TI) tracks its operations across three UNC clusters (UNC6240, UNC6661, UNC6671) to account for evolving partnerships and compartmentalization.

In 2026, ShinyHunters escalated to exploitation of a critical vulnerability — Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8, RCE, no authentication required) — to breach 100+ organisations across 300+ PeopleSoft instances between May 27 and June 9 alone (per Google/Mandiant June 11 disclosure). This represents a significant TTP shift: earlier operations relied primarily on vishing and SaaS credential theft; the PeopleSoft campaign added direct vulnerability exploitation at scale.

Tradecraft

  • Initial access — vishing (2026 primary vector): Phone-based social engineering impersonating IT staff; directs employees to victim-branded credential harvesting pages; captures MFA codes via fake "account update" prompts. MeshCentral remote-access agent deployed to establish persistence post-credential capture.
  • Initial access — vulnerability exploitation (2026 secondary vector): Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) exploited over HTTP without authentication; delivered RCE against internet-exposed PeopleSoft HR/payroll/ERP instances. Also observed: Salesforce and SharePoint credential abuse in parallel campaigns (BCD Travel, Sysco).
  • Initial access — SaaS supply chain / OAuth consent abuse (2026 third vector, Microsoft July 13 disclosure): Three-path campaign running mid-2025 to mid-2026 targeting Salesforce environments. Path 1: fake Salesforce Data Loader app deployed via vishing tricks employees into OAuth consent grant — attacker inherits the authenticated session without capturing credentials. Path 2: compromise of Salesloft Drift integration credentials (August 2025) exposed OAuth connection secrets shared across 700+ customer Salesforce tenants (confirmed exposed: Cloudflare, Zscaler, Palo Alto Networks, Proofpoint, PagerDuty, Tanium). Path 3: Salesforce Aura guest access exploitation — chaining framework requests allowed guest-tier accounts to exfiltrate data volumes beyond their authorization scope. Microsoft has shipped OAuth risk scores into Defender/Entra to detect anomalous consent patterns.
  • Lateral movement: SSH credential spraying using harvested application-layer passwords; scripts parse /etc/hosts to enumerate internal hosts; SaaS integration pivoting (OAuth token theft to access connected apps — Salesforce, Gong, Okta, Google Workspace, Slack).
  • Exfiltration targets: HR/payroll databases, student information systems, customer PII, corporate communications (SharePoint/email), facial recognition and threat assessment data.
  • Monetization: Countdown-timer extortion (72-hour deadlines, Bitcoin demands); data published on ShinyHunters DLS if deadline missed; group claims permanent retention and distribution via mirrors and torrent networks (announced June 2026). Some victims have reportedly paid; "shred logs" provided post-payment (reliability unverified). Group does not deploy ransomware or encrypt systems.

Notable victims

  • Instructure/Canvas (attack April 25, 2026; disclosed May 1; ransom paid May 11) — 275 million users across 8,809 institutions worldwide; largest educational data breach on record. Malwarebytes · Bitdefender
  • Council of Europe (June 14 claim; June 16 data published) — 297 GB HR/payroll/personnel data for 10,000+ staff; 409,000+ payslips (2011–2026), 14,000+ CVs, bank account and tax/Social Security records; Oracle PeopleSoft CVE-2026-35273 claimed vector. SecurityWeek · BleepingComputer
  • Madison Square Garden Sports Corp. (breach June 5; data published June 16) — 45 GB / 26M records including facial recognition surveillance records and internal threat assessments. The Next Web
  • University of Nottingham (attack May 27–June 9; disclosed June 11, 2026) — 454,600+ student and alumni records including passport numbers, ethnicity and disability information; Oracle PeopleSoft CVE-2026-35273 confirmed vector. BleepingComputer · The Register
  • BCD Travel (data published June 2, 2026) — 396,313 customer email addresses and 700,000+ Salesforce records (30 GB+); direct Salesforce/SharePoint compromise. Cybernews
  • Wynn Resorts (September 2025 intrusion; confirmed February 24, 2026) — 21,000 employees and 800,000+ records including SSNs; ransom reportedly paid (~22 BTC / ~$1.5M). SecurityWeek
  • Carnival Corporation / Holland America (April 14, 2026; notified May 27) — 5,995,277 individuals; passport and driver's license numbers exposed. BleepingComputer
  • Polmed (polmed.co.za) (seen April 18, 2026) — 214 GB; 1.7M SAPS member records including 68,000 active officer numbers, undercover officer designations, home addresses, bank account details, and mental health diagnostic codes; initial access via abandoned SAP consultant account retaining domain-admin rights; $1M ransom demand; Polmed board approved R67M emergency response (Mandiant IR + member credit protection); the presence of undercover officer designations makes this the highest-sensitivity breach in the group's history with direct national security implications for South Africa. Cape Town Today · ITWeb · Malwarebytes
  • Nissan North America (disclosed June 29-30, 2026) — 53,000+ current and former employees across US, Canada, Mexico, and Brazil; SSNs, Social Insurance Numbers (Canada), payroll records, banking/direct-deposit details, W-2/tax data, and dependent/beneficiary info; Oracle PeopleSoft CVE-2026-35273 attack window May 27–June 9, 2026; Nissan activated IR and notified law enforcement; multi-country regulatory exposure under US state laws, PIPEDA, LFPDPPP, and Brazil LGPD. The Register · SC Media
  • Questel SAS (breach Aug 1–13, confirmed Aug 13, 2026) — French IP and patent management firm; vishing call gave attacker access to a Sales SharePoint site in Microsoft 365 (not Salesforce, as originally claimed); 21M+ record claim disputed by Questel; data published post-confirmation. Questel notified CNIL and filed criminal complaints. SQ Magazine
  • Baxter International (claim Aug 14, 2026; deadline Aug 17) — US medical technology firm; 7.1M Salesforce records with PII claimed. As of Aug 22, no data published. 🟥 Unverified. HookPhish
  • Alcon Inc. (claim Aug 2, 2026; deadline Aug 4) — Swiss ophthalmology firm; 25M+ Salesforce records claimed. 218,395 email addresses published post-deadline (B2B contact data only; far below claimed volume). 🟨 Partial. TechNadu
  • Lumenis (claim Aug 2, 2026; deadline Aug 4) — Israeli medical devices firm; 1.1M+ records claimed. As of Aug 22, no data published. 🟥 Unverified.
  • Logitech / Streamlabs (claim Aug 18, 2026; deadline Aug 21) — Swiss peripherals maker and its Streamlabs streaming platform; scope not stated. As of Aug 22, no data published. 🟥 Unverified. Cyber Daily
  • Prior major victims include Tokopedia (91M, 2020), Microsoft GitHub repos (December 2020), AT&T (73M, March 2024, data subsequently published on BreachForums). Historical victim count exceeds 60 confirmed breaches (April 2020–July 2021 alone, per DOJ indictment).

Assessment

ShinyHunters remains the most operationally capable and financially successful data-extortion group globally as of mid-to-late 2026, with 55+ breach claims in 2026 YTD. The 2026 Oracle PeopleSoft campaign — confirmed by Mandiant across 100+ organisations and 300+ instances (May 27–June 9 alone) — demonstrates the group has graduated from opportunistic credential theft to coordinated zero-day exploitation at scale. The Polmed breach (April 18, disclosed mid-2026) represents a qualitative escalation beyond financially motivated extortion: 68,000 active South African Police Service officer numbers and undercover designations in a live criminal dataset constitute a persistent national security risk that the group has announced it will retain permanently via mirrors and torrent networks, rendering ransom payment irrelevant to data recovery. The Nissan North America breach (disclosed June 29-30, 2026) confirmed the PeopleSoft campaign extended into the patching window and spans four countries simultaneously. The Microsoft July 13 disclosure of the Salesforce OAuth supply-chain campaign (mid-2025 to mid-2026) adds a third distinct attack methodology alongside vishing and vulnerability exploitation: ShinyHunters is now confirmed to operate sustained multi-vector SaaS supply chain campaigns targeting widely deployed third-party integration vendors (Salesloft Drift, Gainsight) to gain silent persistent API access across hundreds of downstream customer tenants. This tradecraft is significantly harder to detect than credential-based attacks because OAuth tokens issued to legitimate vendors appear benign in log telemetry until the vendor's infrastructure is compromised. The Council of Europe, Instructure/Canvas (275M users), and Polmed breaches collectively signal willingness to target intergovernmental institutions, law enforcement, and mission-critical infrastructure. The decentralized structure, Mandiant's three-cluster tracking (UNC6240/UNC6661/UNC6671), and resilience through arrests make near-term disruption unlikely. The August 2026 wave (Questel, Alcon, Baxter International, Logitech/Streamlabs) demonstrates a continuing Salesforce-credential campaign targeting enterprises with large Salesforce deployments, using vishing as the primary initial access vector. The gap between claimed data volumes and published data on Alcon (25M claimed; 218K published) suggests the group inflates claims to maximize ransom pressure — a pattern worth tracking as a confidence indicator on future claims. Organisations running Oracle PeopleSoft, Salesforce integrations with third-party vendors, or large-scale SaaS environments should treat ShinyHunters as an active threat requiring immediate patching (CVE-2026-35273 June 2026 Oracle CPU), periodic OAuth consent grant review and revocation, scope restriction on third-party Salesforce apps, vishing awareness training, and anomaly detection on OAuth token usage patterns.

Sources

🗂️ Attacks & victims

All disclosed victims attributed to this actor, newest first.

September 2026

Sep 08 Florida DAVID (Highway Safety and Motor Vehicles) ShinyHunters Extortion · Government · USA ShinyHunters claims access to Florida's DAVID driver/vehicle lookup database via a password-reset flaw compromising DMV-employee and FBI-agent accounts; ~200,000 driver records allegedly pulled by iterating IDs starting around Sep 3. Proof includes a screenshot of Jeffrey Epstein's DMV record. Verify before treating as a confirmed breach — FLHSMV has not confirmed the claim; leak-site deadline set for Sep 11. · Sources: https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/

August 2026

Aug 25 McKesson Corporation ShinyHunters Extortion · Healthcare · USA ShinyHunters claimed theft of 284M patient data records via third-party application compromise; McKesson confirmed the incident in an SEC 8-K and launched investigation; data allegedly includes names, SSNs, DOBs, patient IDs, Medicaid numbers, medical records, medications — 284M is raw record count, unique individual count TBD; claim unverified · Sources: https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/
Aug 22 BOK Financial ShinyHunters Extortion · Financial Services · USA ShinyHunters DLS claim Aug 22 2026; BOK Financial is a major US financial holding company (NASDAQ: BOKF, ~$50B assets, Tulsa OK); ransom deadline August 24; data scope not disclosed; 🟥 unverified DLS claim · Sources: DEXpose · RansomLook
Aug 22 NovoCure ShinyHunters Extortion · Healthcare / Medical Devices · USA ShinyHunters DLS claim Aug 22 2026; NovoCure (NYSE: NVCR) makes Tumor Treating Fields cancer-treatment devices; data scope and deadline not publicly confirmed; 🟥 unverified DLS claim · Sources: RansomLook
Aug 18 Logitech ShinyHunters Extortion · Technology / Consumer Electronics · USA ShinyHunters DLS claim August 18 2026 against Logitech and its Streamlabs streaming platform; payment deadline set for August 21; data scope and scale unconfirmed; no public statement from Logitech as of August 21 · Sources: https://www.cyberdaily.au/security/14076-pay-or-leak-shinyhunters-delivers-ultimatum-to-logitech
Aug 14 Baxter International ShinyHunters Extortion · Healthcare / Medical Technology · USA ShinyHunters DLS claim August 14 2026 against Baxter International; 7.1 million Salesforce records with PII claimed; extortion deadline was August 17; as of August 22 no data has been published · Sources: https://www.hookphish.com/blog/ransomware-group-shinyhunters-hits-baxter-international-inc/
Aug 01 Questel SAS ShinyHunters Extortion · Intellectual Property Management · France ShinyHunters DLS posting August 1 2026 with August 4 contact deadline; claims 21M+ Salesforce records plus 147 GB internal corporate data; Questel is a major IP and patent management firm serving global enterprise clients; no statement from Questel; data not yet published · Sources: https://breachnews.com/breaches/shinyhunters-lists-questel-alcon-and-lumenis-on-leak-site-with-new-extortion-claims/ https://www.dexpose.io/shinyhunters-breach-questel-sas-french-ip-giant-under-siege/
Aug 01 Alcon Inc. ShinyHunters Extortion · Medical Devices / Ophthalmology · Switzerland ShinyHunters DLS posting August 1 2026 with August 4 contact deadline; claims 25M+ Salesforce records with PII; Alcon is a global ophthalmology medical device and pharmaceutical company; no statement from Alcon; data not yet published · Sources: https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-alcon-inc/ https://www.dexpose.io/shinyhunters-breach-alcon-inc/
Aug 01 Lumenis Ltd. ShinyHunters Extortion · Medical Devices / Laser Systems · Israel ShinyHunters DLS posting August 1 2026 with August 4 contact deadline; claims 1.1M+ customer and employee records plus 176 GB internal corporate data; Lumenis manufactures surgical and aesthetic laser systems; no statement from Lumenis; data not yet published · Sources: https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-lumenis-ltd/ https://breachnews.com/breaches/shinyhunters-lists-questel-alcon-and-lumenis-on-leak-site-with-new-extortion-claims/

July 2026

Jul 31 Brinks Home ShinyHunters Extortion · Security Services · US ShinyHunters claims breach via Microsoft Entra vishing attack July 13; detected by Brinks July 20; claimed: 4.9M+ Salesforce records including 1.1M customer contacts, 3.8M customer support chat logs (Cresta), 4000+ employee PII rows; CEO confirmed breach, alarm monitoring unaffected · Sources: https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/ https://www.theregister.com/security/2026/07/31/the-most-famous-brand-in-physical-security-got-pwned-by-shinyhunters/5281924
Jul 27 Ernst and Young ShinyHunters Extortion · Professional Services · US Supply-chain compromise of third-party IT service management platform Mar 28-Apr 12 2026; yielded credentials to EY Jira, GitHub, Azure; client tax documents with SSNs and financial data; July 31 2026 deadline issued · Sources: https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
Jul 18 Abbott Laboratories (Exact Sciences) ShinyHunters Extortion · healthcare (medical devices / cancer diagnostics) · US Abbott confirmed Jul 18, 2026 unauthorized access to limited systems in Cancer Diagnostics (Exact Sciences) business; ShinyHunters DLS claim alleges exfil of Microsoft Entra/ServiceNow/SharePoint/Databricks/Coupa data; claims: 30M+ rows customer PII, 1M+ SSNs, 22M+ medical order records, doctor-patient notes, NDAs; DLS deadline extended to Jul 21; ShadowByt3$ claims separate LabCentral portal breach under parallel investigation; Abbott has not confirmed data theft scope; 🟥 unverified · Sources: https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/ · https://cybernews.com/news/abbott-laboratories-breach-shinyhunters/ · https://www.abbott.com/en-us/corpnewsroom/diagnostics-testing/abbott-statement-on-cyber-incident-in-cancer-diagnostics-business
Jul 02 Fluke Corporation ShinyHunters Extortion · electronics · test-and-measurement manufacturing/US global manufacturer of electronic test and measurement equipment (subsidiary of Fortive Corporation; >3,000 employees); ShinyHunters DLS claim July 2, 2026 — over 21 million Salesforce records claimed including employee/customer PII; group described failed negotiations with victim before publishing; data scope unconfirmed; no Fluke or Fortive public statement; 🟥 unverified · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-fluke-corporation/ · https://www.ransomware.live/group/shinyhunters · Sources: [RedPacket Security] · [ransomware.live]
Jul 02 Ingram Content Group ShinyHunters Extortion · publishing services · book distribution/US major US book distribution, print-on-demand, and publishing-services company serving thousands of publishers worldwide; ShinyHunters DLS claim July 2, 2026; group alleged failed negotiations with victim; Salesforce data exfiltration claimed; data scope unconfirmed; no public statement from Ingram; 🟥 unverified · https://breachnews.com/breaches/shinyhunters-adds-ingram-content-group-and-fluke-corporation-to-leak-site/ · https://www.hendryadrian.com/ransom-ingram-content-group-inc-jul-2026/ · Sources: [BreachNews] · [hendryadrian.com]

June 2026

Jun 29 Nissan North America ShinyHunters Extortion · automotive · US+Canada+Mexico+Brazil 53,000+ current and former employees across four countries; data includes SSNs (US), Social Insurance Numbers (Canada), payroll records, banking/direct-deposit details, W-2/tax data, and dependent/beneficiary info; Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) attack window May 27–June 9, 2026; Nissan activated IR and engaged external cybersecurity specialists; notified law enforcement; multi-country regulatory exposure under US state notification laws, Canada PIPEDA, Mexico LFPDPPP, and Brazil LGPD · https://www.theregister.com/security/2026/06/29/nissan-says-oracle-peoplesoft-break-in-may-have-spilled-payroll-records-ssns/5263534 · https://www.scworld.com/brief/nissan-confirms-employee-data-exposed-in-oracle-peoplesoft-cyberattack · https://www.infosecurity-magazine.com/news/employees-social-security-nissan/ · Sources: [The Register] · [SC Media] · [Infosecurity Magazine]
Jun 24 Adapt ShinyHunters Extortion · sector unknown · US ShinyHunters DLS claim June 24, 2026; final warning issued with data-leak deadline June 25, 2026 midnight NY time; data volume and type unconfirmed; no victim statement; 🟥 unverified · https://www.dexpose.io/shinyhunters-launches-ransomware-attack-on-adapt/ · Sources: [DeXpose]
Jun 18 Inter-Con Security Systems ShinyHunters Extortion · physical security services · US provider of armed/unarmed security officers, risk management, executive protection, and facility security for government, corporate, and critical infrastructure; 2.7M records claimed; ShinyHunters DLS June 18, 2026; no victim statement · https://www.dexpose.io/shinyhunters-compromise-ic-security-in-major-ransomware-attack/ · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-icsecurity-com/ · https://www.breachsense.com/breaches/inter-con-security-systems-data-breach/ · Sources: [DeXpose] · [RedPacket Security] · [Breachsense]
Jun 16 Moody Bible Institute ShinyHunters Extortion · education · US 1,300+ files claimed; group alleged "tens of millions of records" related to enrollment, donor relations, payroll, and communications; Oracle PeopleSoft CVE-2026-35273 attack vector; DLS claim June 16, 2026; scope unverified; law firm class action investigation underway — 🟥 unverified · https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit · https://www.classaction.org/data-breach-lawsuits/moody-bible-institute-june-2026 · Sources: [Google Cloud Blog] · [classaction.org]
Jun 15 Kodak ShinyHunters Extortion · media technology · US 2.2M records (customer PII and internal corporate data); ShinyHunters listed June 15 with a June 18 ransom deadline; Kodak confirmed "unauthorized third party illegally gained temporary access to a limited amount of company data" June 17 and engaged cybersecurity experts and law enforcement; no proof sample published; no data dump confirmed; claimed vector: Oracle PeopleSoft CVE-2026-35273 · https://cybernews.com/security/shinyhunters-claims-kodak-hack-2-million-records/ · https://www.bleepingcomputer.com/news/security/kodak-confirms-data-breach-claimed-by-shinyhunters-extortion-gang/ · https://www.techtimes.com/articles/318565/20260617/kodak-confirms-data-breach-shinyhunters-threatens-leak-22m-records.htm · Sources: [Cybernews] · [BleepingComputer] · [TechTimes]
Jun 15 Sysco ShinyHunters Extortion · food distribution · US 61M Salesforce records claimed; ShinyHunters listed June 15, weeks after Sysco was separately targeted by Qilin ransomware (two distinct threat actors targeting the same org); Sysco has not publicly confirmed this incident; 🟥 unverified — treat as claimed only · https://cybernews.com/news/sysco-shinyhunters-61-million-salesforce-records/ · Sources: [Cybernews]
Jun 15 Glendale Community College ShinyHunters Extortion · education · US 62GB exfiltrated (304,000+ files); Oracle PeopleSoft Campus Solutions compromised via CVE-2026-35273; 150,000+ student records including names, DOBs, student emails, enrollment, financial aid, and transcript data (Sept 2020–June 2026); DLS claim June 15–16, 2026; final ransom warning before June 18 deadline · https://www.ransomware.live/id/Z2xlbmRhbGUuZWR1QHNoaW55aHVudGVycw · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-glendale-edu/ · https://cybernews.com/security/google-shinyhunters-oracle-peoplesoft-zero-day-extortion/ · Sources: [ransomware.live] · [RedPacket Security] · [Cybernews]
Jun 15 Illinois Central College ShinyHunters Extortion · education · US 28GB data claimed; Oracle PeopleSoft CVE-2026-35273 attack vector; DLS claim June 15, 2026; final ransom warning issued · https://www.dexpose.io/shinyhunters-breach-illinois-central-college/ · https://www.breachsense.com/breaches/illinois-central-college-data-breach/ · Sources: [DeXpose] · [Breachsense]
Jun 15 Deep Well Services ShinyHunters Extortion · oilfield services · US provider of downhole tools and services to the oil and gas industry; 7,000+ customer PII and internal corporate data records claimed; ShinyHunters DLS June 15, 2026; ransom deadline June 18 passed without data publication at time of initial report; no victim statement · https://www.hookphish.com/blog/ransomware-group-shinyhunters-hits-deep-well-services/ · https://www.ransomware.live/id/RGVlcCBXZWxsIFNlcnZpY2VzQHNoaW55aHVudGVycw · https://breachnews.com/breaches/kodak-and-deep-well-services-added-to-shinyhunters-leak-site/ · Sources: [HookPhish] · [ransomware.live] · [BreachNews]
Jun 14 Council of Europe ShinyHunters Extortion · intergovernmental organisation · France 297 GB published June 16, 2026, after ransom deadline not met; content: 409,000+ payslips (2011–2026), 3,700+ personnel files, 14,000+ CVs, and employee personal/financial records (names, DOB, home addresses, phone, salaries, bank account details, SSN/tax information, medical records) for 10,000+ staff; claimed access vector: Oracle PeopleSoft CVE-2026-35273; Council of Europe states investigation is ongoing; data authenticity not yet independently verified by forensics · https://www.securityweek.com/shinyhunters-claims-council-of-europe-hack/ · https://www.bleepingcomputer.com/news/security/council-of-europe-investigates-shinyhunters-data-breach-claims/ · https://cybernews.com/security/council-of-europe-data-breach-claim/ · Sources: [SecurityWeek] · [BleepingComputer] · [Cybernews]
Jun 13 One Medical ShinyHunters Extortion · healthcare · US legacy One Medical Seniors patient file storage compromised (demographic + clinical records, 9 US cities: Atlanta, Cape Cod, Charlotte, Piedmont Triad, Denver, Houston, Phoenix, Tucson, Seattle); 8.8TB claimed; breach June 8-11, detected June 13; ShinyHunters deadline June 22; company confirmed unauthorized access; core EHR and non-Seniors systems unaffected; vector unconfirmed (not PeopleSoft CVE-2026-35273) · https://www.hipaajournal.com/one-medical-data-breach/ · https://cybernews.com/security/amazon-one-medical-data-breach/ · https://www.bankinfosecurity.com/shinyhunters-threatens-to-leak-amazon-one-medical-records-a-32027 · Sources: [HIPAA Journal] · [Cybernews] · [BankInfoSecurity]
Jun 12 JCPenney / Catalyst Brands / Authentic Brands Group ShinyHunters Extortion · retail · US hundreds of thousands of records claimed (SSNs, DOBs, W-2 tax forms, payroll records, driver's licenses, government-issued IDs); ShinyHunters claimed June 12; threatened to publish by June 15; no JCPenney/Catalyst/Authentic public statement; class action investigation launched (Edelson Lechtzin LLP, June 18); no data samples published; 🟥 unverified — treat as claimed only · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-jcpenney-several-other-subsdiaries-under-catalyst-brands-authentic-brands-group/ · https://cybernews.com/security/shinyhunters-jcpenney-retail-data-leak-claim/ · https://www.dexpose.io/shinyhunters-breaches-jcpenney-and-catalyst-brands/ · Sources: [RedPacket Security] · [Cybernews] · [DeXpose]
Jun 12 American Tower Corporation ShinyHunters Extortion · telecommunications infrastructure · US 5.2M records claimed including customer and landowner PII, records linking T-Mobile/Verizon/US DHS as clients, tower asset GPS coordinates, and plaintext physical access/gate codes for cell tower compounds across the US; claimed June 12, ransom deadline June 15 (passed with no confirmed data dump); company has not issued a public statement; 🟥 unverified — treat as claimed only · https://www.dexpose.io/shinyhunters-breach-american-tower-corporation/ · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-american-tower-corporation/ · https://www.breachsense.com/breaches/american-tower-data-breach/ · Sources: [DeXpose] · [RedPacket Security] · [Breachsense]
Jun 12 Zayo Group + Allstream ShinyHunters Extortion · telecommunications · US+Canada ShinyHunters claimed June 12, 2026 with a June 16 payment-or-leak deadline; data scope unconfirmed; no victim statement · https://www.dexpose.io/shinyhunters-target-zayo-group-and-allstream-in-ransomware-attack/ · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-zayo-com-allstream-com/ · https://www.ransomware.live/id/WmF5by5jb20gJiBBbGxzdHJlYW0uY29tQHNoaW55aHVudGVycw · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 11 National Association of Insurance Commissioners ShinyHunters Extortion · insurance regulatory · US 3.1TB and 105,000+ files claimed; investigation confirmed (July 1): only publicly available statutory financial reports, outdated logs, and config files accessed; key systems SERFF/OPTins/UCAA/EDP/RDC confirmed intact; no consumer PII or payment data; breach via PeopleSoft CVE-2026-35273, access June 11; data published online by June 25; 🟩 breach confirmed, impact minimal (public regulatory data only) · https://www.insurancejournal.com/news/national/2026/06/24/875119.htm · https://www.bleepingcomputer.com/news/security/naic-says-public-data-stolen-in-shinyhunters-peoplesoft-breach/ · https://www.techradar.com/pro/security/naic-confirms-data-breach-with-shinyhunters-claiming-3-1tb-of-data-stolen-in-oracle-zero-day-attack · Sources: [Insurance Journal] · [BleepingComputer] · [TechRadar]
Jun 09 University of Nottingham ShinyHunters Extortion · education · UK 454,600+ student and alumni records including names, addresses, phone numbers, passport numbers, ethnicity and disability data, and academic records; Oracle PeopleSoft CVE-2026-35273 confirmed access vector (attack window May 27–June 9); university confirmed incident June 11, 2026 · https://www.bleepingcomputer.com/news/security/nottingham-university-data-breach-affects-over-450-000-students/ · https://www.theregister.com/cyber-crime/2026/06/11/shinyhunters-raids-nottingham-uni-for-student-alumni-data/5253961 · https://www.helpnetsecurity.com/2026/06/11/oracle-peoplesoft-under-attack-cve-2026-35273/ · Sources: [BleepingComputer] · [The Register] · [Help Net Security]
Jun 09 Houston City College ShinyHunters Extortion · education · US Oracle PeopleSoft CVE-2026-35273 attack vector; DLS claim first posted June 9 onwards; named victim confirmed in Google Cloud/Mandiant ShinyHunters education sector campaign report (June 2026) · https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit · https://www.highereddive.com/news/colleges-hit-in-cyberattack-by-group-behind-canvas-breach-google-says/822831/ · Sources: [Google Cloud Blog] · [Higher Ed Dive]
Jun 05 Madison Square Garden Sports Corp. ShinyHunters Extortion · entertainment · sports/US 45 GB published June 16 (26M customer and corporate records); content includes facial recognition surveillance records, internal threat assessments, and personal customer data; breach June 5, ransom deadline June 15, deadline missed, data published June 16; MSG's second major breach within 6 months (prior: Cl0p/Oracle eBusiness Suite February 2026, 131,070 employees/contractors); claimed vector: Oracle PeopleSoft CVE-2026-35273 · https://thenextweb.com/news/shinyhunters-madison-square-garden-45gb-data-leak-facial-recognition · https://www.dexpose.io/shinyhunters-breach-madison-square-garden-sports-corp/ · Sources: [The Next Web] · [DeXpose]

May 2026

May 27 Carnival Corporation ShinyHunters Extortion · travel · hospitality/US 5,995,277 individuals affected; names, dates of birth, addresses, email, phone, passport and driver's license numbers; social-engineering attack on Carnival employee led to account compromise April 14, 2026; data exfiltrated before access blocked; breach notification letters dated May 27, 2026 · https://www.bleepingcomputer.com/news/security/carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people/ · https://www.theregister.com/cyber-crime/2026/05/28/carnival-shinyhunters-cruised-off-with-6m-customer-records/5247808 · https://www.malwarebytes.com/blog/data-breaches/2026/05/carnival-confirms-data-breach-impacting-nearly-6-million · Sources: [BleepingComputer] · [The Register] · [Malwarebytes]
May 23 DentaQuest ShinyHunters Extortion · dental benefits administration · US 2.6M members' PII and PHI exposed (names, DOBs, email, phone, home addresses, gender, government-issued IDs, health insurance info, Medicaid IDs); 234GB exfiltrated; ShinyHunters posted May 23, data published after ransom negotiation failure; DentaQuest confirmed breach June 2, 2026; 2,553,599 unique emails confirmed via HIBP June 3; attack vector unconfirmed · https://securityaffairs.com/193274/data-breach/dentaquest-breach-shinyhunters-publish-data-impacting-2-6m-people.html · https://www.bankinfosecurity.com/shinyhunters-leaks-234gb-dentaquest-data-trove-a-31883 · https://www.rescana.com/post/dentaquest-data-breach-analysis-shinyhunters-leak-exposes-pii-and-phi-of-2-6-million-members-in-2026 · https://www.hipaajournal.com/dentaquest-data-breach/ · Sources: [SecurityAffairs] · [BankInfoSecurity] · [Rescana] · [HIPAA Journal]
May 01 BCD Travel ShinyHunters Extortion · travel services · Netherlands 396,313 customer email addresses and 700,000+ Salesforce records (30 GB+ compressed) published after June 1 ransom deadline; data includes names, physical addresses, phone numbers, job titles, and support tickets; access via direct Salesforce/SharePoint compromise (not Oracle PeopleSoft CVE-2026-35273) · https://cybernews.com/security/shinyhunters-400k-bcd-travel-customers-data-online/ · https://www.dutchnews.nl/2026/06/dutch-travel-firm-bcd-hacked-700000-customers-reportedly-hit/ · Sources: [Cybernews] · [DutchNews.nl]
May 01 Cushman & Wakefield ShinyHunters Extortion · commercial real estate services · US 500,000+ Salesforce records (310,400 accounts confirmed via HIBP May 12); names, job titles, company addresses, phone numbers, email addresses; vishing attack May 1 2026; 50GB data published May 7 after ransom talks failed (May 6 deadline); Qilin also listed Cushman & Wakefield on DLS May 4 — relationship unconfirmed, may reflect separate opportunistic access; access via Salesforce (not PeopleSoft CVE-2026-35273) · https://cybernews.com/security/shinyhunters-cushman-wakefield-salesforce-dataset-leak/ · https://www.theregister.com/security/2026/05/05/cushman-wakefield-confirms-vishing-cyberattack/5228718/ · https://socradar.io/blog/charter-data-breach-shinyhunters-42m-records/ · Sources: [Cybernews] · [The Register] · [SOCRadar]

April 2026

Apr 25 Instructure/Canvas ShinyHunters Extortion · education technology platform · US 275 million users across 8,809 universities, educational ministries, and institutions worldwide; attack April 25, 2026; Instructure detected intrusion April 29 and revoked access; disclosed May 1; data includes student names, email addresses, student ID numbers, and user messages; described as the largest educational data breach on record; Instructure paid ransom, "shred logs" provided May 11; FBI warned students and staff of ongoing phishing risk post-ransom · https://www.malwarebytes.com/blog/news/2026/05/millions-of-students-personal-data-stolen-in-major-education-cyberattack · https://www.bitdefender.com/en-us/blog/hotforsecurity/canvas-data-breach-2026 · Sources: [Malwarebytes] · [Bitdefender]
Apr 24 Udemy ShinyHunters Extortion · education technology · US 1.4 million records claimed; listed DLS April 24, data published April 27 after ransom deadline; no Udemy public confirmation — 🟥 unverified · https://cybernews.com/security/shinyhunters-claim-udemy-data-theft/ · https://www.scworld.com/brief/udemy-allegedly-breached-by-shinyhunters-data-leak-warned · Sources: [Cybernews] · [SC Media]
Apr 21 Zara ShinyHunters Extortion · fashion retail · Spain 197,400 customer emails, product order data (order IDs, SKUs, market of purchase); Anodot/BigQuery SaaS supply chain (not PeopleSoft CVE-2026-35273); ransom deadline April 21, data published April 22 after deadline; Inditex confirmed "unauthorized access to BigQuery data via a retired third-party analytics provider" early May 2026; HIBP added May 8; no passwords or payment data affected · https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/ · https://securityaffairs.com/191859/cyber-crime/zara-data-breach-197000-customers-exposed-in-third-party-security-incident.html · https://www.infosecurity-magazine.com/news/zara-data-breach-impacts-200000/ · Sources: [BleepingComputer] · [SecurityAffairs] · [Infosecurity Magazine]
Apr 21 7-Eleven ShinyHunters Extortion · retail · convenience stores/Japan 600,000+ Salesforce CRM records; listed DLS April 21-27, 2026; data published after ransom deadline; Salesforce environment vector (not PeopleSoft CVE-2026-35273); no 7-Eleven public confirmation — 🟥 unverified · https://cybernews.com/news/shinyhunters-myteresa-zara-carnival-7eleven-data-leak/ · https://www.techradar.com/pro/security/shinyhunters-exposes-data-on-mytheresa-zara-carnival-7-eleven-over-40-organizations-tied-up-in-new-data-trove-which-will-stay-up-indefinitely · Sources: [Cybernews] · [TechRadar]
Apr 20 ADT ShinyHunters Extortion · home security · US 5.5M individuals affected (names, phone numbers, physical addresses; partial SSNs and DOBs for subset); vishing attack on ADT employee Okta SSO credentials → attacker pivoted to Salesforce CRM; breach detected April 20, access confirmed revoked April 24; ShinyHunters claimed 10M records; ADT confirmed 5.5M via HIBP notification; ADT filed breach notification and notified law enforcement; Salesforce vector (not Oracle PeopleSoft CVE-2026-35273) · https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/ · https://www.bankinfosecurity.com/home-security-firm-adt-breach-55m-customers-data-exposed-a-31511 · https://www.rescana.com/post/adt-salesforce-data-breach-2026-shinyhunters-compromise-okta-sso-via-vishing-attack · Sources: [BleepingComputer] · [BankInfoSecurity] · [Rescana]
Apr 18 Polmed ShinyHunters Extortion · healthcare · medical scheme/South Africa Police Medical Benefits Scheme serving South African Police Service (SAPS) members and their families; 214 GB claimed; 1.7M member records exposed including 68,000 active SAPS employee numbers, home addresses, bank account details, mental health diagnostic codes, and undercover officer designations (creating national security exposure); initial access via password-spray on abandoned SAP consultant account last active 2019 but retaining domain-admin rights; ShinyHunters $1M ransom demand; Polmed board approved R67M emergency response budget (Mandiant IR retainer + credit-protection cover for all members + remediation costs); undercover officer identifiers in the dataset represent the highest-sensitivity element of this breach · https://capetown.today/news/massive-police-data-breach-raises-national-security-alarm-in-south-africa · https://www.itweb.co.za/article/saps-medical-aid-scheme-probes-potential-data-breach/P3gQ2MGA5VNvnRD1 · https://www.malwarebytes.com/blog/news/2026/05/biometrics-diagnoses-and-bank-details-exposed-in-major-healthcare-breach · Sources: [Cape Town Today] · [ITWeb] · [Malwarebytes]
Apr 13 Medtronic ShinyHunters Extortion · medical devices · US global medical device manufacturer; breach April 13–19, 2026 via third-party vendor credential compromise; 3.8M individuals affected (names, contact information, product/service history; scope confirmed per Medtronic's HIPAA breach notification to HHS/OCR); customer notification letters sent July 2, 2026; class action investigation opened; medical devices and patient safety systems confirmed unaffected; 🟨 breach confirmed by Medtronic, group attribution based on ShinyHunters DLS · https://www.securityweek.com/medtronic-discloses-data-breach-impacting-3-8-million-people/ · https://www.hipaajournal.com/medtronic-data-breach-3-8-million/ · https://www.bleepingcomputer.com/news/security/medtronic-discloses-data-breach-impacting-38-million-customers/ · https://therecord.media/medtronic-data-breach-3-million · Sources: [SecurityWeek] · [HIPAA Journal] · [BleepingComputer] · [The Record]
Apr 12 Mytheresa ShinyHunters Extortion · fashion e-commerce · Germany data published post-deadline; Anodot/BigQuery SaaS supply chain vector (same vector as Rockstar Games; not PeopleSoft CVE-2026-35273); no Mytheresa public confirmation — 🟥 unverified · https://cybernews.com/news/shinyhunters-myteresa-zara-carnival-7eleven-data-leak/ · https://www.techradar.com/pro/security/shinyhunters-exposes-data-on-mytheresa-zara-carnival-7-eleven-over-40-organizations-tied-up-in-new-data-trove-which-will-stay-up-indefinitely · Sources: [Cybernews] · [TechRadar]
Apr 12 Marcus & Millichap ShinyHunters Extortion · commercial real estate brokerage · US 30M Salesforce records claimed including employee/client PII and internal corporate data; ShinyHunters claimed April 12, 2026; HIBP confirmed; no Marcus & Millichap public statement · https://www.dexpose.io/shinyhunters-target-marcus-millichap-in-major-ransomware-attack/ · https://haveibeenpwned.com/Breach/MarcusMillichap · https://www.hookphish.com/blog/ransomware-group-shinyhunters-hits-marcus-and-millichap-inc/ · https://www.breachsense.com/breaches/marcus-and-millichap-data-breach/ · Sources: [DeXpose] · [HIBP] · [HookPhish] · [Breachsense]
Apr 11 Rockstar Games ShinyHunters Extortion · gaming · technology/US 78.6M records claimed (GTA Online/Red Dead Online analytics, internal business metrics); breach April 11 via Anodot (third-party SaaS analytics) → Snowflake; ransom deadline April 14 missed, partial data published; Rockstar confirmed "limited, non-material" information; Snowflake confirmed breach was Anodot credential compromise, not Snowflake infrastructure; SaaS supply chain vector (not PeopleSoft CVE-2026-35273) · https://www.benzinga.com/markets/tech/26/04/51795873/rockstar-games-data-breach-80-million-records-anodot-snowflake · https://www.bitdefender.com/en-us/blog/hotforsecurity/rockstar-games-data-breach · https://www.deepwatch.com/labs/ca-a-26-006-shinyhunters-breaches-rockstar-games-via-third-party-cloud-integration/ · Sources: [Benzinga] · [Bitdefender] · [DeepWatch]
Apr 09 Pitney Bowes ShinyHunters Extortion · business services · logistics technology/US 8,243,989 unique customer email addresses + names, phone numbers, physical addresses (business customer Salesforce contacts); phishing attack April 8 harvested employee credentials; attacker used credentials to access Salesforce CRM and exfiltrate records; Pitney Bowes confirmed breach, secured environment, notified law enforcement; HIBP confirmed 8.2M records April 27; no SSNs or payment data accessed · https://www.theregister.com/2026/04/28/pitney_bowes_is_the_latest/ · https://www.dexpose.io/shinyhunters-breach-pitney-bowes-inc/ · https://www.teiss.co.uk/news/pitney-bowes-confirms-cyber-intrusion-as-shinyhunters-claims-breach-of-millions-of-records-17436 · Sources: [The Register] · [DeXpose] · [teiss]
Apr 01 Charter Communications ShinyHunters Extortion · telecommunications · US 40-42M records claimed (13M+ individually confirmed); names, email/physical addresses, phone numbers, subscription plan details, support tickets, CPNI; vishing attack April 1 2026 targeting Microsoft Entra credentials; attacker pivoted to Salesforce CRM; Charter disclosed publicly May 26 one day before ShinyHunters' May 27 ransom deadline; 50GB data published after ransom refusal; Charter disputes CPNI exfiltration, ShinyHunters disputes claim with screenshots; access via Salesforce/Entra (not PeopleSoft CVE-2026-35273); among the largest US telecom breaches on record · https://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/ · https://www.techradar.com/pro/security/charter-communications-confirms-data-breach-shinyhunters-blamed-after-threat-to-leak-user-info-online/ · https://www.scworld.com/brief/shinyhunters-extorts-charter-communications-after-data-breach · Sources: [BleepingComputer] · [TechRadar] · [SC Media]

March 2026

Mar 18 Infinite Campus ShinyHunters Extortion · education technology · US student information system serving 3,200+ school districts and 11M students across 46 US states; Salesforce account vishing attack March 18, 2026; 137,123 unique school staff accounts' data exfiltrated: names, email addresses, phone numbers, physical addresses, job titles, usernames, and support tickets; Infinite Campus confirmed breach (staff data only; no evidence student databases compromised); HIBP notification June 15, 2026; Salesforce vector (not PeopleSoft CVE-2026-35273) · https://www.bleepingcomputer.com/news/security/infinite-campus-data-breach-affects-137-000-school-staff-accounts/ · https://cybernews.com/cybercrime/shinyhunters-data-infinite-campus-137k-students-exposed/ · https://www.techradar.com/pro/security/11-million-students-possibly-at-risk-after-classroom-software-used-by-millions-hacked · Sources: [BleepingComputer] · [Cybernews] · [TechRadar]

February 2026

Feb 24 Wynn Resorts ShinyHunters Extortion · hospitality · US 21,000 employees affected; 800,000+ records claimed including full names, SSNs, dates of birth, email addresses, and phone numbers; unauthorized access identified September 2025; Wynn confirmed breach February 24, 2026; ShinyHunters removed Wynn from DLS after ransom reportedly paid (~22 BTC / ~$1.5M); SEC 8-K filed · https://www.securityweek.com/wynn-resorts-says-21000-employees-affected-by-shinyhunters-hack/ · https://www.bleepingcomputer.com/news/security/wynn-resorts-confirms-employee-data-breach-after-extortion-threat/ · Sources: [SecurityWeek] · [BleepingComputer]

← All threat actors · Full victim database →