# ShinyHunters

> As of 2026-10-05, ShinyHunters is a France-nexus threat actor tracked by Threadlinqs Intelligence across 28 threats spanning threat intel, data breach, vulnerability. Also known as UNC6040, UNC6240, Scattered LAPSUS$ Hunters, Scattered Spider. ATT&CK coverage spans 168 techniques across 15 tactics in 28 of 28 tracked threats. Most-observed techniques: T1657 (Financial Theft), T1213 (Data from Information Repositories), T1528 (Steal Application Access Token).

- **Nation:** France
- **Tracked threats:** 28
- **Categories:** THREAT_INTEL, DATA_BREACH, VULNERABILITY, PHISHING, RANSOMWARE, APT, SUPPLY_CHAIN, THREAT_ACTOR, CAMPAIGN
- **Also known as:** UNC6040, UNC6240, Scattered LAPSUS$ Hunters, Scattered Spider, LAPSUS$, The Com, ShinyCorp, Shiny Hunters, ShinyHunters impersonator, Sp1d3rHunters, Hollywood Hunters, Sh1nyHunters
- **As of:** 2026-10-05

## ATT&CK techniques observed

168 techniques observed across 28 of 28 tracked threats. Tactics: Resource Development (22), Credential Access (21), Reconnaissance (17), Discovery (16), Stealth (formerly Defense Evasion) (16), Persistence (15).

- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 23 of 28 tracked threats
- [T1213](https://intel.threadlinqs.com/technique/T1213) Data from Information Repositories — Collection — observed in 19 of 28 tracked threats
- [T1528](https://intel.threadlinqs.com/technique/T1528) Steal Application Access Token — Credential Access — observed in 19 of 28 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 19 of 28 tracked threats
- [T1199](https://intel.threadlinqs.com/technique/T1199) Trusted Relationship — Initial Access — observed in 18 of 28 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 17 of 28 tracked threats
- [T1530](https://intel.threadlinqs.com/technique/T1530) Data from Cloud Storage — Collection — observed in 17 of 28 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 12 of 28 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 11 of 28 tracked threats
- [T1537](https://intel.threadlinqs.com/technique/T1537) Transfer Data to Cloud Account — Exfiltration — observed in 11 of 28 tracked threats
- [T1550](https://intel.threadlinqs.com/technique/T1550) Use Alternate Authentication Material — Lateral Movement — observed in 11 of 28 tracked threats
- [T1552](https://intel.threadlinqs.com/technique/T1552) Unsecured Credentials — Credential Access — observed in 11 of 28 tracked threats
- [T1583](https://intel.threadlinqs.com/technique/T1583) Acquire Infrastructure — Resource Development — observed in 11 of 28 tracked threats
- [T1526](https://intel.threadlinqs.com/technique/T1526) Cloud Service Discovery — Discovery — observed in 10 of 28 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 9 of 28 tracked threats

## Tracked threats

- [ShinyHunters: alleged leader 'Rey' (Saif al-Din Khader) detained in Jordan and reportedly cooperating with the FBI; Dutch suspect Pepijn van der Stap ('Umbreon') arrested](https://intel.threadlinqs.com/threat/TL-2026-2945) — MEDIUM
- [ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing Agent and Applicant Personal Data](https://intel.threadlinqs.com/threat/TL-2026-2760) — HIGH
- [ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak Site](https://intel.threadlinqs.com/threat/TL-2026-2671) — CRITICAL
- [Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem](https://intel.threadlinqs.com/threat/TL-2026-2663) — INFORMATIONAL
- [ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak](https://intel.threadlinqs.com/threat/TL-2026-2620) — CRITICAL
- [ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour Extortion](https://intel.threadlinqs.com/threat/TL-2026-2584) — MEDIUM
- [ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and Salesforce/Snowflake Compromise](https://intel.threadlinqs.com/threat/TL-2026-2208) — CRITICAL
- [Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign Targeting Microsoft 365 Accounts](https://intel.threadlinqs.com/threat/TL-2026-1871) — HIGH
- [Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys](https://intel.threadlinqs.com/threat/TL-2026-1793) — HIGH
- [Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 2026 Data Breach Notices — 275M Records, 8,809 Institutions Extorted](https://intel.threadlinqs.com/threat/TL-2026-1705) — CRITICAL
- [Ransomware Negotiation Tactics: ShinyHunters/Scattered LAPSUS$ Hunters Instructure Canvas Breach (280M Records, May 2026) and Historical Ragnar Locker (CWT Global) / NetWalker (UCSF) Extortion Payments](https://intel.threadlinqs.com/threat/TL-2026-1476) — HIGH
- [Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns](https://intel.threadlinqs.com/threat/TL-2026-1347) — HIGH
- [ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce Access](https://intel.threadlinqs.com/threat/TL-2026-1311) — HIGH
- [ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS Integrations](https://intel.threadlinqs.com/threat/TL-2026-1275) — HIGH
- [Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted](https://intel.threadlinqs.com/threat/TL-2026-0804) — HIGH
- [ShinyHunters (UNC6240) Exploits Oracle PeopleSoft PeopleTools CVE-2026-35273 Zero-Day to Compromise 100+ Higher-Education Organizations](https://intel.threadlinqs.com/threat/TL-2026-0779) — CRITICAL
- [NVIDIA GeForce NOW Armenian Data Breach via GFN.am Alliance Partner Compromise — ShinyHunters-Branded PII Theft](https://intel.threadlinqs.com/threat/TL-2026-0485) — HIGH
- [ShinyHunters Mass Defacement of Canvas LMS — Instructure Re-Breach Extortion Campaign Affecting ~330 Educational Institutions (May 2026)](https://intel.threadlinqs.com/threat/TL-2026-0482) — HIGH
- [ShinyHunters Breach of Instructure Canvas LMS via Free-For-Teacher Program](https://intel.threadlinqs.com/threat/TL-2026-2124) — HIGH
- [Vercel April 2026 Security Incident — Context.ai OAuth Supply Chain Compromise Exposing Employee Records, Plaintext Environment Variables, and npm/GitHub Tokens](https://intel.threadlinqs.com/threat/TL-2026-0400) — HIGH
- [Vercel April 2026 Security Incident — Context.ai OAuth Compromise Leads to Google Workspace Takeover and Customer Environment Variable Exposure](https://intel.threadlinqs.com/threat/TL-2026-0394) — HIGH
- [ShinyHunters Leaks 5.1 Million Panera Bread Customer Records](https://intel.threadlinqs.com/threat/TL-2026-0055) — HIGH
- [ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-0054) — HIGH
- [ShinyHunters-Branded Extortion Campaign Expands with Vishing & SSO Attacks](https://intel.threadlinqs.com/threat/TL-2026-0045) — HIGH
- [SLSH Extortion Group - Swatting and Executive Harassment Tactics](https://intel.threadlinqs.com/threat/TL-2026-0035) — HIGH
- [Panera Bread Data Breach - 5.1 Million Accounts Exposed](https://intel.threadlinqs.com/threat/TL-2026-0031) — MEDIUM
- [ShinyHunters Extortion Campaign - Evolved Vishing and SSO Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-0030) — HIGH
- [ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering](https://intel.threadlinqs.com/threat/TL-2026-0013) — CRITICAL

## Related CVEs

4 CVEs referenced by tracked ShinyHunters activity.

- [CVE-2026-42608](https://intel.threadlinqs.com/cve/CVE-2026-42608)
- [CVE-2026-35273](https://intel.threadlinqs.com/cve/CVE-2026-35273)
- [CVE-2025-61882](https://intel.threadlinqs.com/cve/CVE-2025-61882)
- [CVE-2021-21425](https://intel.threadlinqs.com/cve/CVE-2021-21425)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/ShinyHunters
