Home · Wiki · Entities & Threat Actors
type: entity · created: 2026-08-28 · updated: 2026-08-28 · tags: [cybercrime-group, le-action, campaign, supply-chain] · confidence: high · affected_sectors: [technology, healthcare, retail, finance, education, media] · au_impact: true

ShinyHunters

ShinyHunters (leader persona shinycorp; affiliated with The Com) is a black-hat criminal hacker and data-extortion group active since about 2020. It is among the most prolific data-theft and extortion operations in the world, built around large-scale credential theft, SaaS/cloud intrusions and a "pay-or-leak" extortion model rather than bare ransomware encryption. Its name derives from Shiny Pokémon — "shiny hunting" in the Pokémon games. It overlaps heavily with Scattered Spider and cybercrime forums such as The Com.(raw/digests/Cyber-Digest-2026-08-28.md)

TTPs

  • Large-scale SaaS / cloud data theft from Microsoft 365, SharePoint, OneDrive, Salesforce, Slack, Okta and similar platforms, then exfiltration and extortion.
  • Vishing and Okta/Entra SSO phishing: impersonated Okta SSO login pages and voice-phishing calls to steal credentials from high-value enterprise users (investment banking, luxury retail, travel, payment processing). 2026 activity tracked by Mandiant/Google Threat Intelligence as UNC6661 / UNC6671.
  • Supply-chain / integrator pivots: gained access through third-party platforms and integrators — including Anodot → Snowflake — to reach downstream customers (a repeat of the 2024 Snowflake campaign).
  • Extortion mechanics: demand emails signed "ShinyHunters", follow-on six- to seven-figure ransom demands (BTC), 72-hour deadlines, sample leaks via LimeWire and Tox negotiation, and a ShinyHunters-branded data-leak site on Tor. Uses a delayed extortion model — victims who pay have sometimes had data leaked anyway.
  • Oracle Access Manager exploitation (CVE-2021-35587) via hard-coded credentials and SQL*Plus data exfiltration.

Notable campaigns and breaches

  • 2020–2021: early sale/leak of hundreds of millions of records (BigBasket ~20M, Tokopedia ~91M, and the 2021 sale of 70M+ AT&T subscriber records — AT&T only acknowledged the breach in 2024).
  • 2024 — Snowflake customer campaign: the campaign that made the group infamous — Ticketmaster (~560M records, $500K asking price), AT&T (~110M call records; AT&T paid ~$370K to delete data), Santander (~30M), Neiman Marcus (~31M), Advance Auto Parts, LendingTree, Bausch Health and others; access via an EPAM Systems supply-chain breach and Snowflake credentials stored unencrypted in Jira.
  • 2025: SoundCloud (~29.8M accounts, Dec 2025), Pornhub (Premium member data threat), and a Salesforce data-leak site extorting 39 victims (Oct 2025).
  • 2026 Okta/Entra SSO campaign: Panera (~5M, Jan), Grubhub, Figure (~1M, Feb), Wynn Resorts (~800K, Feb), Odido (~6M, Feb), Aura (~900K, Mar), Betterment (~1.4M, Feb), Telus/Telus Digital (~1 PB claimed, $65M demand, Mar), European Commission (~350 GB, Mar — attributed by CERT-EU), Rockstar Games (~80M claimed via Anodot→Snowflake, Apr), ADT (~5.5M via Okta vishing, Apr), Carnival Cruise (~6M, Apr), McGraw Hill (~13.5M, Apr), Instructure/Canvas (~275M records/3.65TB, Apr–May — reached a ransom agreement with the group), University of Nottingham (Jun), MSG Sports (45 GB leaked, Jun), RingCentral (~1.6M, Jul).
  • 2026 — Australian-relevant recent incidents: Baxter International (~7.1M alleged Salesforce records, Aug), Carhartt (~12.9M accounts via its Databricks analytics platform, Aug — HIBP-verified), and the failed ReliaQuest vishing attack (Aug).

Scale

ShinyHunters has been linked to breaches touching hundreds of millions of records across a wide swathe of sectors — ticketing, telecoms, banking, retail, hospitality, healthcare, education, media and government. It sells stolen datasets (sometimes with ransomware affiliates/other eCrime actors) at prices exceeding US$1M per company.

Attribution and law enforcement

  • Real-world identity remains largely unknown; researchers describe the name more as a brand than a fixed crew, possibly tied to GnosticPlayers and to Scattered Spider (0ktapus/Muddled Libra/Starfraud). A claimed "Scattered Lapsus$ Hunters" supergroup has been reported.
  • Arrests have not stopped operations: French national Sébastien Raoult was arrested (May 2022) and extradited to the US over ShinyHunters-linked activity, yet the brand continued shipping breaches. Vercel's April 2026 breach claim was denied by ShinyHunters' actual leadership — a sign the name is now used by copycats.

Australian angle

ShinyHunters is a direct and repeated threat to Australian and New Zealand organisations and consumers. Health-ISAC has warned of its increasing targeting of healthcare data — directly relevant under APRA CPS 234 and the OAIC Notifiable Data Breaches scheme given AU health sector concentration risk. The Baxter and Carhartt breaches expose AU/NZ retail and health consumers to downstream phishing and fraud; AU/NZ retailers should treat analytics/data platforms (Databricks, Salesforce, Snowflake) holding customer data as a widening target. See also Health Isac Warns Of Increasing Shinyhunters Healthcare Data Theft Attacks. Au Impact

Related Pages