Threat Intelligence / Actor / Greatness PhaaS Operators
Greatness PhaaS Operators
As of 2026-08-25, Greatness PhaaS Operators is a Russia (Storm-2372 attribution, medium confidence); criminal actors are not state-affiliated-nexus threat actor tracked by Threadlinqs Intelligence across 21 threats spanning phishing, data breach, ransomware. Also known as ShinyHunters (related RingCentral breach), Multiple: Storm-2372, Multiple: Storm-2372 (nation-state), Scattered LAPSUS$ Hunters.
Also known as: Greatness PhaaS Operators, ShinyHunters, ShinyHunters (related RingCentral breach), Multiple: Storm-2372, Multiple: Storm-2372 (nation-state), Scattered LAPSUS$ Hunters, Scattered LAPSUS$ Hunters (criminal), commodity PhaaS kit operators (EvilTokens, ARToken, Tycoon2FA, Kali365, 25
Tracked threats
- Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign Targeting Microsoft 365 Accounts — HIGH
- Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys — HIGH
- Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 2026 Data Breach Notices — 275M Records, 8,809 Institutions Extorted — CRITICAL
- Ransomware Negotiation Tactics: ShinyHunters/Scattered LAPSUS$ Hunters Instructure Canvas Breach (280M Records, May 2026) and Historical Ragnar Locker (CWT Global) / NetWalker (UCSF) Extortion Payments — HIGH
- Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns — HIGH
- ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce Access — HIGH
- ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS Integrations — HIGH
- Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted — HIGH
- ShinyHunters (UNC6240) Exploits Oracle PeopleSoft PeopleTools CVE-2026-35273 Zero-Day to Compromise 100+ Higher-Education Organizations — CRITICAL
- NVIDIA GeForce NOW Armenian Data Breach via GFN.am Alliance Partner Compromise — ShinyHunters-Branded PII Theft — HIGH
- ShinyHunters Mass Defacement of Canvas LMS — Instructure Re-Breach Extortion Campaign Affecting ~330 Educational Institutions (May 2026) — HIGH
- ShinyHunters Breach of Instructure Canvas LMS via Free-For-Teacher Program — HIGH
- Vercel April 2026 Security Incident — Context.ai OAuth Supply Chain Compromise Exposing Employee Records, Plaintext Environment Variables, and npm/GitHub Tokens — HIGH
- Vercel April 2026 Security Incident — Context.ai OAuth Compromise Leads to Google Workspace Takeover and Customer Environment Variable Exposure — HIGH
- ShinyHunters Leaks 5.1 Million Panera Bread Customer Records — HIGH
- ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypass — HIGH
- ShinyHunters-Branded Extortion Campaign Expands with Vishing & SSO Attacks — HIGH
- SLSH Extortion Group - Swatting and Executive Harassment Tactics — HIGH
- Panera Bread Data Breach - 5.1 Million Accounts Exposed — MEDIUM
- ShinyHunters Extortion Campaign - Evolved Vishing and SSO Credential Theft — HIGH
- ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering — CRITICAL
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →