Threadlinqs IntelligenceStart free

Threat actorFranceTracked since 2026-02

ShinyHunters

Also known as:UNC6040UNC6240Scattered LAPSUS$ HuntersScattered SpiderLAPSUS$The ComShinyCorpShiny HuntersShinyHunters impersonatorSp1d3rHuntersHollywood HuntersSh1nyHunters

As of 2026-10-05, ShinyHunters is a France-nexus threat actor tracked by Threadlinqs Intelligence across 28 threats spanning threat intel, data breach, vulnerability. Also known as UNC6040, UNC6240, Scattered LAPSUS$ Hunters, Scattered Spider. ATT&CK coverage spans 168 techniques across 15 tactics in 28 of 28 tracked threats. Most-observed techniques: T1657 (Financial Theft), T1213 (Data from Information Repositories), T1528 (Steal Application Access Token).

Tracked threats
286 critical · 18 high · 3 medium
First seen
2026-02-02
Last seen
2026-10-05
ATT&CK techniques
168across 28 of 28 threats
Related CVEs
4Referenced by its activity
Attribution
FranceNation or origin
Nation: France · 28 tracked threat(s) · Categories: THREAT_INTEL, DATA_BREACH, VULNERABILITY, PHISHING, RANSOMWARE, APT, SUPPLY_CHAIN, THREAT_ACTOR, CAMPAIGN

Activity timeline

ShinyHunters appears in 28 tracked threats between and ; the busiest month was 2026-02 with 7 reports.

ATT&CK techniques observed

168 techniques observed across 28 of 28 tracked threats · Resource Development (22), Credential Access (21), Reconnaissance (17), Discovery (16), Stealth (formerly Defense Evasion) (16), Persistence (15)
  • T1657 Financial Theft — Impactobserved in 23 of 28 tracked threats
  • T1213 Data from Information Repositories — Collectionobserved in 19 of 28 tracked threats
  • T1528 Steal Application Access Token — Credential Accessobserved in 19 of 28 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 19 of 28 tracked threats
  • T1199 Trusted Relationship — Initial Accessobserved in 18 of 28 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 17 of 28 tracked threats
  • T1530 Data from Cloud Storage — Collectionobserved in 17 of 28 tracked threats
  • T1566 Phishing — Initial Accessobserved in 12 of 28 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 11 of 28 tracked threats
  • T1537 Transfer Data to Cloud Account — Exfiltrationobserved in 11 of 28 tracked threats
  • T1550 Use Alternate Authentication Material — Lateral Movementobserved in 11 of 28 tracked threats
  • T1552 Unsecured Credentials — Credential Accessobserved in 11 of 28 tracked threats
  • T1583 Acquire Infrastructure — Resource Developmentobserved in 11 of 28 tracked threats
  • T1526 Cloud Service Discovery — Discoveryobserved in 10 of 28 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 9 of 28 tracked threats

Tracked threats

Related CVEs

4 CVEs referenced by tracked ShinyHunters activity