Activity timeline
ShinyHunters appears in 28 tracked threats between and ; the busiest month was 2026-02 with 7 reports.
ATT&CK techniques observed
- T1657 Financial Theft — Impactobserved in 23 of 28 tracked threats
- T1213 Data from Information Repositories — Collectionobserved in 19 of 28 tracked threats
- T1528 Steal Application Access Token — Credential Accessobserved in 19 of 28 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltrationobserved in 19 of 28 tracked threats
- T1199 Trusted Relationship — Initial Accessobserved in 18 of 28 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 17 of 28 tracked threats
- T1530 Data from Cloud Storage — Collectionobserved in 17 of 28 tracked threats
- T1566 Phishing — Initial Accessobserved in 12 of 28 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 11 of 28 tracked threats
- T1537 Transfer Data to Cloud Account — Exfiltrationobserved in 11 of 28 tracked threats
- T1550 Use Alternate Authentication Material — Lateral Movementobserved in 11 of 28 tracked threats
- T1552 Unsecured Credentials — Credential Accessobserved in 11 of 28 tracked threats
- T1583 Acquire Infrastructure — Resource Developmentobserved in 11 of 28 tracked threats
- T1526 Cloud Service Discovery — Discoveryobserved in 10 of 28 tracked threats
- T1087 Account Discovery — Discoveryobserved in 9 of 28 tracked threats
Tracked threats
- ShinyHunters: alleged leader 'Rey' (Saif al-Din Khader) detained in Jordan and reportedly cooperating with the FBI; Dutch suspect Pepijn van der Stap ('Umbreon') arrestedMEDIUM
- ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing Agent and Applicant Personal DataHIGH
- ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak SiteCRITICAL
- Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem
- ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI LeakCRITICAL
- ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour ExtortionMEDIUM
- ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and Salesforce/Snowflake CompromiseCRITICAL
- Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign Targeting Microsoft 365 AccountsHIGH
- Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including PasskeysHIGH
- Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 2026 Data Breach Notices — 275M Records, 8,809 Institutions ExtortedCRITICAL
- Ransomware Negotiation Tactics: ShinyHunters/Scattered LAPSUS$ Hunters Instructure Canvas Breach (280M Records, May 2026) and Historical Ragnar Locker (CWT Global) / NetWalker (UCSF) Extortion PaymentsHIGH
- Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters CampaignsHIGH
- ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce AccessHIGH
- ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS IntegrationsHIGH
- Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and ExtortedHIGH
- ShinyHunters (UNC6240) Exploits Oracle PeopleSoft PeopleTools CVE-2026-35273 Zero-Day to Compromise 100+ Higher-Education OrganizationsCRITICAL
- NVIDIA GeForce NOW Armenian Data Breach via GFN.am Alliance Partner Compromise — ShinyHunters-Branded PII TheftHIGH
- ShinyHunters Mass Defacement of Canvas LMS — Instructure Re-Breach Extortion Campaign Affecting ~330 Educational Institutions (May 2026)HIGH
- ShinyHunters Breach of Instructure Canvas LMS via Free-For-Teacher ProgramHIGH
- Vercel April 2026 Security Incident — Context.ai OAuth Supply Chain Compromise Exposing Employee Records, Plaintext Environment Variables, and npm/GitHub TokensHIGH
- Vercel April 2026 Security Incident — Context.ai OAuth Compromise Leads to Google Workspace Takeover and Customer Environment Variable ExposureHIGH
- ShinyHunters Leaks 5.1 Million Panera Bread Customer RecordsHIGH
- ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA BypassHIGH
- ShinyHunters-Branded Extortion Campaign Expands with Vishing & SSO AttacksHIGH
- SLSH Extortion Group - Swatting and Executive Harassment TacticsHIGH
- Panera Bread Data Breach - 5.1 Million Accounts ExposedMEDIUM
- ShinyHunters Extortion Campaign - Evolved Vishing and SSO Credential TheftHIGH
- ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social EngineeringCRITICAL