ShinyHunters
ShinyHunters (leader persona shinycorp; affiliated with The Com) is a black-hat criminal hacker and data-extortion group active since about 2020. It is among the most prolific data-theft and extortion operations in the world, built around large-scale credential theft, SaaS/cloud intrusions and a "pay-or-leak" extortion model rather than bare ransomware encryption. Its name derives from Shiny Pokémon — "shiny hunting" in the Pokémon games. It overlaps heavily with Scattered Spider and cybercrime forums such as The Com.(raw/digests/Cyber-Digest-2026-08-28.md)
TTPs
- Large-scale SaaS / cloud data theft from Microsoft 365, SharePoint, OneDrive, Salesforce, Slack, Okta and similar platforms, then exfiltration and extortion.
- Vishing and Okta/Entra SSO phishing: impersonated Okta SSO login pages and voice-phishing calls to steal credentials from high-value enterprise users (investment banking, luxury retail, travel, payment processing). 2026 activity tracked by Mandiant/Google Threat Intelligence as UNC6661 / UNC6671.
- Supply-chain / integrator pivots: gained access through third-party platforms and integrators — including Anodot → Snowflake — to reach downstream customers (a repeat of the 2024 Snowflake campaign).
- Extortion mechanics: demand emails signed "ShinyHunters", follow-on six- to seven-figure ransom demands (BTC), 72-hour deadlines, sample leaks via LimeWire and Tox negotiation, and a ShinyHunters-branded data-leak site on Tor. Uses a delayed extortion model — victims who pay have sometimes had data leaked anyway.
- Oracle Access Manager exploitation (CVE-2021-35587) via hard-coded credentials and SQL*Plus data exfiltration.
Notable campaigns and breaches
- 2020–2021: early sale/leak of hundreds of millions of records (BigBasket ~20M, Tokopedia ~91M, and the 2021 sale of 70M+ AT&T subscriber records — AT&T only acknowledged the breach in 2024).
- 2024 — Snowflake customer campaign: the campaign that made the group infamous — Ticketmaster (~560M records, $500K asking price), AT&T (~110M call records; AT&T paid ~$370K to delete data), Santander (~30M), Neiman Marcus (~31M), Advance Auto Parts, LendingTree, Bausch Health and others; access via an EPAM Systems supply-chain breach and Snowflake credentials stored unencrypted in Jira.
- 2025: SoundCloud (~29.8M accounts, Dec 2025), Pornhub (Premium member data threat), and a Salesforce data-leak site extorting 39 victims (Oct 2025).
- 2026 Okta/Entra SSO campaign: Panera (~5M, Jan), Grubhub, Figure (~1M, Feb), Wynn Resorts (~800K, Feb), Odido (~6M, Feb), Aura (~900K, Mar), Betterment (~1.4M, Feb), Telus/Telus Digital (~1 PB claimed, $65M demand, Mar), European Commission (~350 GB, Mar — attributed by CERT-EU), Rockstar Games (~80M claimed via Anodot→Snowflake, Apr), ADT (~5.5M via Okta vishing, Apr), Carnival Cruise (~6M, Apr), McGraw Hill (~13.5M, Apr), Instructure/Canvas (~275M records/3.65TB, Apr–May — reached a ransom agreement with the group), University of Nottingham (Jun), MSG Sports (45 GB leaked, Jun), RingCentral (~1.6M, Jul).
- 2026 — Australian-relevant recent incidents: Baxter International (~7.1M alleged Salesforce records, Aug), Carhartt (~12.9M accounts via its Databricks analytics platform, Aug — HIBP-verified), and the failed ReliaQuest vishing attack (Aug).
Scale
ShinyHunters has been linked to breaches touching hundreds of millions of records across a wide swathe of sectors — ticketing, telecoms, banking, retail, hospitality, healthcare, education, media and government. It sells stolen datasets (sometimes with ransomware affiliates/other eCrime actors) at prices exceeding US$1M per company.
Attribution and law enforcement
- Real-world identity remains largely unknown; researchers describe the name more as a brand than a fixed crew, possibly tied to GnosticPlayers and to Scattered Spider (0ktapus/Muddled Libra/Starfraud). A claimed "Scattered Lapsus$ Hunters" supergroup has been reported.
- Arrests have not stopped operations: French national Sébastien Raoult was arrested (May 2022) and extradited to the US over ShinyHunters-linked activity, yet the brand continued shipping breaches. Vercel's April 2026 breach claim was denied by ShinyHunters' actual leadership — a sign the name is now used by copycats.
Australian angle
ShinyHunters is a direct and repeated threat to Australian and New Zealand organisations and consumers. Health-ISAC has warned of its increasing targeting of healthcare data — directly relevant under APRA CPS 234 and the OAIC Notifiable Data Breaches scheme given AU health sector concentration risk. The Baxter and Carhartt breaches expose AU/NZ retail and health consumers to downstream phishing and fraud; AU/NZ retailers should treat analytics/data platforms (Databricks, Salesforce, Snowflake) holding customer data as a widening target. See also Health Isac Warns Of Increasing Shinyhunters Healthcare Data Theft Attacks. Au Impact
Related Pages
- Scattered Spider — overlapping, collaborating cybercrime group (0ktapus / Muddled Libra)
- Shinyhunters Leaks 7 1 Million Records Claimed From Medical Device Maker Baxter — ShinyHunters Baxter International breach (Aug 2026)
- Carhartt Breach Shinyhunters Releases Data Of 12 9 Million Accounts — ShinyHunters Carhartt breach (Aug 2026)
- Reliaquest Failed Shinyhunters Vishing Attack 2026 08 24 — the failed ReliaQuest vishing attack