ShinyHunters Extortion Campaign - Evolved Vishing and SSO Credential Theft
ShinyHunters Extortion Campaign (TL-2026-0030), also tracked as ShinyHunters, is a high-severity tracked intrusion set scored CVSS 8.2, first published 2026-02-02. It is attributed to ShinyHunters (France) with high confidence, affects N/A Enterprise SSO Systems, maps to 31 MITRE ATT&CK techniques (T1020, T1059, T1074), and is covered by 13 detection rules and 63 indicators of compromise.
Key facts for TL-2026-0030
- Threat ID
- TL-2026-0030
- Also known as
- ShinyHunters, Scattered Spider Tactics, Help Desk Social Engineering
- Severity
- HIGH
- CVSS
- 8.2 (N/A - Social Engineering Campaign)
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-02-02
- Last reviewed
- 2026-02-02
- Attribution
- ShinyHunters
- Attribution confidence
- HIGH
- Nation-state nexus
- France
- Motivation
- FINANCIAL
- Target sectors
- Telecommunications, Entertainment, Financial Services, Technology, SaaS Providers, Retail, Healthcare, Government
- Target regions
- North America, Europe, Global
- Detection rules
- 13
- Indicators of compromise
- 63
Malware and tooling in ShinyHunters Extortion Campaign
Malware and tooling: VIDAR, RISEPRO, REDLINE, RACCOON STEALER, LUMMA, METASTEALER — infostealer malware families, VIDAR/RISEPRO/REDLINE/RACCOON/LUMMA/METASTEALER infostealer logs containing Snowflake credentials, DBeaver Ultimate — database management utility used for interactive Snowflake SQL queries, FROSTBITE — custom Snowflake reconnaissance utility (.NET and Java variants)
ShinyHunters has evolved from a dark web data broker into one of the most impactful financially-motivated threat groups of 2024-2026, orchestrating the Snowflake customer data theft campaign (UNC5537) that compromised 165+ organizations including AT&T (110M records), Ticketmaster/Live Nation (560M records), and Santander Bank (30M records). The group's operational evolution traces four distinct phases: data breach marketplace operator (2020-2022) → phishing kit adoption (2022-2023) → vishing-based help desk social engineering (2023-2024) → infostealer credential harvesting at industrial scale for SaaS platform targeting (2024-2026). The Snowflake campaign demonstrated a paradigm shift: rather than exploiting vulnerabilities, UNC5537 systematically compromised customer instances using stolen credentials from infostealer malware (VIDAR, RISEPRO, REDLINE, RACCOON STEALER, LUMMA, METASTEALER) — some dating to 2020 — against accounts lacking MFA. The group developed a custom reconnaissance tool (FROSTBITE) and used DBeaver Ultimate for SQL-based data staging and exfiltration via Snowflake's native COPY INTO → GET pipeline. SIM-swapping serves as a secondary identity theft vector for MFA bypass when accounts do have MFA enabled. ShinyHunters monetizes through dual extortion: selling stolen data on BreachForums while simultaneously extorting victims directly. The Snowflake campaign is the largest single-platform credential-based breach campaign in history, exposing the catastrophic risk of credential reuse, absent MFA, and the robust infostealer marketplace ecosystem.
How ShinyHunters Extortion Campaign works
ShinyHunters emerged circa 2020 as a prolific data breach operator, initially stealing and selling databases from GitHub private repos, Tokopedia (91M records), Mashable, Bonobos, Pixlr, Wattpad (270M records), and dozens more targets via RaidForums and later BreachForums. Core member Sebastien Raoult (SeyzoKaizen) was arrested in Morocco (2022) and convicted in US federal court (2024). Despite arrests, the group's operational capability expanded rather than contracted.
THE SNOWFLAKE CAMPAIGN (UNC5537) — SPRING/SUMMER 2024:
Mandiant tracks the Snowflake targeting cluster as UNC5537, a financially motivated threat actor with members based in North America and at least one collaborator in Turkey. The campaign represents ShinyHunters' evolution from traditional database theft to SaaS platform credential exploitation at industrial scale.
CAMPAIGN MECHANICS:
1. CREDENTIAL HARVESTING: UNC5537 aggregated Snowflake customer credentials from multiple infostealer malware families: VIDAR, RISEPRO, REDLINE, RACCOON STEALER, LUMMA, and METASTEALER. The earliest stolen credential dated to November 2020 — still valid 4 years later. At least 79.7% of compromised accounts had prior credential exposure via infostealers. Credentials were purchased from the underground infostealer marketplace and harvested from historical stealer log collections.
2. CONTRACTOR VECTOR: In several cases, initial infostealer compromise occurred on contractor systems used for personal activities including gaming and pirated software downloads. A single compromised contractor laptop provided access to multiple organizations with IT/admin-level Snowflake privileges.
3. ACCESS: UNC5537 accessed Snowflake instances via the native web UI (SnowSight), CLI tool (SnowSQL), and a custom reconnaissance utility dubbed FROSTBITE (available in .NET and Java variants). FROSTBITE performed SQL reconnaissance: listing users, current roles, IPs, session IDs, and organization names. DBeaver Ultimate was used for interactive query execution.
4. DATA STAGING: Systematic SQL pipeline: - SHOW TABLES → enumerate all databases and tables - SELECT * FROM target tables - CREATE TEMPORARY STAGE → create ephemeral staging area - COPY INTO @stage → compress data as GZIP CSV (5GB max file size) - GET @stage → exfiltrate to local attacker system
5. INFRASTRUCTURE: Mullvad and Private Internet Access (PIA) VPN for access. ALEXHOST SRL (AS200019, Moldova) VPS for staging. MEGA cloud storage for stolen data.
6. MONETIZATION: Dual extortion — victims contacted directly for ransom payment + stolen data advertised on BreachForums and Telegram channels.
THREE PRIMARY FAILURE FACTORS (per Mandiant): - Impacted accounts were NOT configured with MFA - Credentials had NOT been rotated (some valid since 2020) - NO network allow lists to restrict access to trusted locations
KNOWN VICTIMS: - AT&T: ~110 million customer call and text records stolen from Snowflake instance - Ticketmaster/Live Nation: ~560 million customer records stolen and offered for $500K on BreachForums - Santander Bank: ~30 million customer and employee records compromised - 165+ total organizations notified by Mandiant and Snowflake
VISHING EVOLUTION (2023-2026):
Parallel to the Snowflake campaign, ShinyHunters and affiliated actors developed sophisticated vishing (voice phishing) capabilities targeting enterprise help desks:
- Impersonating employees using stolen PII from prior breaches (employee ID, manager name, birthday, last 4 SSN) - Requesting MFA factor resets and password resets via phone calls to IT help desks - 30-60% success rate for well-researched vishing calls vs 5-15% for email phishing - SSO provider targeting: Okta, Azure AD (Entra ID), OneLogin, Duo - Help desk verification bypass exploits static knowledge-based verification (all answers available from prior breaches) - MGM Resorts and Caesars Entertainment breaches (2023) used this methodology via affiliated Scattered Spider actors
SIM-SWAPPING VECTOR:
ShinyHunters employs SIM-swapping as a secondary MFA bypass technique: - Social engineering mobile carrier employees to transfer victim's phone number to attacker-controlled SIM - Intercepts SMS-based MFA codes for accounts with SMS 2FA enabled - Enables account takeover even when MFA is present (but SMS-based) - Combined with credential theft: stolen password + SIM-swapped phone = full account access - Used against high-value individual targets (executives, admins) when SSO credentials require MFA
VOICE DEEPFAKE ESCALATION:
AI-generated voice clones (ElevenLabs, Resemble AI, open-source TTS) enable real-time voice impersonation in vishing calls with 3-10 seconds of sample audio. This defeats voice-based verification and creates near-perfect employee impersonation when combined with caller ID spoofing and PII-backed identity answers.
SHINYHUNTERS vs SCATTERED SPIDER (TL-0013):
Distinct but overlapping groups: - ShinyHunters: data broker origin, credential marketplace expertise, SaaS platform targeting (Snowflake), infostealer credential aggregation, BreachForums monetization - Scattered Spider (TL-0013): identity infrastructure targeting, SIM-swapping specialization, help desk social engineering, ransomware deployment (ALPHV/BlackCat) - Overlap: shared TTPs (vishing, MFA bypass), some member crossover, both target enterprise SSO - Key distinction: ShinyHunters weaponizes stolen CREDENTIALS at scale; Scattered Spider weaponizes IDENTITY INFRASTRUCTURE
DATA MONETIZATION PIPELINE:
ShinyHunters operates a sophisticated data monetization pipeline: 1. Steal credentials via infostealer malware or purchase from underground markets 2. Access SaaS platforms (Snowflake, cloud storage, SSO portals) using stolen credentials 3. Exfiltrate data using platform-native tools (no malware needed) 4. List data for sale on BreachForums (public advertisement) 5. Simultaneously extort victims directly (private ransom demand) 6. If victim pays: data (allegedly) withheld from public sale 7. If victim doesn't pay: data sold to highest bidder or leaked publicly
This dual-revenue model maximizes financial return per breach while creating urgency for victim payment.
MITRE ATT&CK techniques used in TL-2026-0030
exfiltration
T1020 Automated Exfiltration; T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service
execution
T1059 Command and Scripting Interpreter; T1204 User Execution
collection
T1074 Data Staged; T1119 Automated Collection; T1213 Data from Information Repositories; T1530 Data from Cloud Storage
defense-evasion
persistence
T1098 Account Manipulation; T1098.001 Additional Cloud Credentials
credential-access
T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores; T1556 Modify Authentication Process; T1621 Multi-Factor Authentication Request Generation
initial-access
T1199 Trusted Relationship; T1566 Phishing; T1566.004 Spearphishing Voice
lateral-movement
T1550 Use Alternate Authentication Material
discovery
T1580 Cloud Infrastructure Discovery
resource-development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities
reconnaissance
T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains; T1594 Search Victim-Owned Websites
impact
Affected products and versions in ShinyHunters Extortion Campaign
- N/A — Enterprise SSO Systems
Vulnerable versions: All organizations using SSO
Remediation for ShinyHunters Extortion Campaign
Immediate actions
- Implement callback verification for all MFA reset requests
- Require manager approval for help desk MFA changes
- Alert security team on any MFA reset followed by new device enrollment
- Review recent MFA resets for unauthorized changes
Workarounds
- Require in-person verification for MFA resets
- Implement time delay between MFA reset and new device enrollment
- Use verified employee directory for callback numbers, not caller-provided
Longer-term hardening
- Train help desk staff on vishing attack recognition
- Implement hardware security keys resistant to phishing
- Deploy FIDO2/WebAuthn for phishing-resistant MFA
- Establish out-of-band verification procedures for sensitive requests
Weaknesses (CWE) in ShinyHunters Extortion Campaign
CWE-287, CWE-384
Timeline of ShinyHunters Extortion Campaign
- ShinyHunters emerge as a prolific data breach operator. Initial targets: GitHub private repos, Tokopedia (91M records), Wattpad (270M records), Mashable, Bonobos, Pixlr. Databases sold on RaidForums. Group builds massive PII collection and establishes dark web marketplace presence. Source: BleepingComputer, DataBreaches.net
- Earliest infostealer-harvested Snowflake credential identified by Mandiant during UNC5537 investigation. This credential remained valid and unrotated for nearly 4 years, enabling the 2024 Snowflake campaign. Demonstrates the long tail of credential exposure. Source: Mandiant/Google Cloud
- ShinyHunters at peak marketplace activity selling billions of stolen records on BreachForums and Telegram. Revenue from database sales funds operational evolution. PII databases become reconnaissance foundation for future vishing and impersonation campaigns.
- Sebastien Raoult (SeyzoKaizen), French national and ShinyHunters member, arrested in Morocco on US federal warrant. Extradited to United States. Despite arrest, core ShinyHunters operations continue and evolve under remaining members. Source: DOJ
- ShinyHunters and affiliated actors adopt vishing (voice phishing) targeting enterprise help desks. Live voice social engineering achieves 30-60% success rate vs 5-15% for email phishing. SSO providers (Okta, Azure AD, Duo) targeted via help desk MFA reset requests. Source: CrowdStrike, Mandiant
- Affiliated Scattered Spider actors use vishing to breach MGM Resorts and Caesars Entertainment via help desk social engineering → Okta SSO access. Caesars pays $15M ransom. MGM suffers $100M+ losses. Demonstrates vishing's enterprise-scale impact and convergence with ShinyHunters TTPs. Source: Mandiant, CrowdStrike
- Okta discloses breach of customer support case management system. Attackers accessed HAR files containing session tokens. Linked to Scattered Spider/ShinyHunters ecosystem. SSO providers themselves become targets. Source: Okta advisory
- Sebastien Raoult convicted in US federal court for computer fraud. Sentenced to prison. International law enforcement coordination demonstrated. Core ShinyHunters continue operations via UNC5537 cluster. Source: DOJ
- Mandiant receives threat intelligence on stolen database records traced to a Snowflake customer instance. Investigation reveals compromise via infostealer-stolen credentials. Account had no MFA. This is the first identified victim of the UNC5537 Snowflake campaign. Source: Mandiant/Google Cloud
- Mandiant identifies broader campaign targeting multiple Snowflake customers. Mandiant and Snowflake begin notifying approximately 165 potentially exposed organizations. Snowflake publishes detection and hardening guidance. Joint investigation with law enforcement initiated. Source: Mandiant, Snowflake
- Ticketmaster/Live Nation breach disclosed — ~560 million customer records stolen from Snowflake instance. Data offered for sale on BreachForums for $500,000. One of the largest consumer data breaches in history by record count. Source: SEC filing, BleepingComputer
- Santander Bank confirms ~30 million customer and employee records compromised via Snowflake instance. Data stolen using same UNC5537 credential-based methodology. Financial sector impact demonstrated. Source: Santander disclosure
- Mandiant publishes comprehensive UNC5537 analysis detailing Snowflake campaign: infostealer credential harvesting (VIDAR/RISEPRO/REDLINE/RACCOON/LUMMA/METASTEALER), FROSTBITE reconnaissance tool, DBeaver Ultimate, SQL data staging pipeline, Mullvad/PIA VPN, ALEXHOST staging, MEGA exfiltration. 79.7% of accounts had prior credential exposure. Source: Mandiant/Google Cloud
- Mandiant releases Snowflake Threat Hunting Guide with detection queries and guidance for identifying UNC5537 activity. Default 365-day retention enables historical threat hunting across Snowflake instances. Source: Mandiant
- AT&T discloses ~110 million customer call and text metadata records stolen from Snowflake instance by UNC5537. One of the largest telecom data breaches. Call detail records enable massive surveillance potential. Source: AT&T, SEC filing
- ShinyHunters/UNC5537 continue targeting SaaS platforms with infostealer-harvested credentials. Mandiant assesses pattern will extend to additional SaaS platforms beyond Snowflake. Vishing and SIM-swapping capabilities mature. Voice deepfake integration observed.
- Current state: ShinyHunters/UNC5537 represent the convergence of infostealer credential marketplaces, SaaS platform targeting, vishing-based social engineering, and SIM-swapping MFA bypass. The Snowflake campaign is the largest single-platform credential-based breach in history. MFA enforcement and credential rotation remain the primary defenses.
- As of 2026-05-29, ShinyHunters' credential-theft and vishing extortion campaign remains ACTIVE and escalating, now operating within the "Scattered Lapsus$ Hunters"/"Trinity of Chaos" alliance with fresh 2026 breaches (Instructure/Canvas ~275M records 25 Apr, Pitney Bowes 28 Apr). Despite arrests like Connor Moucka (Oct 2024), the collective's tempo increased, confirming the HIGH-severity status holds; no CVE applies as this is a social-engineering campaign.
Sources cited for ShinyHunters Extortion Campaign
- Mandiant/Google Cloud — UNC5537 Snowflake Data Theft and Extortion
- Snowflake — Detecting and Preventing Unauthorized Access (Joint Advisory)
- Mandiant — Snowflake Threat Hunting Guide
- DOJ — Sebastien Raoult Conviction
- CrowdStrike — Scattered Spider Profile
- Okta — Support System Breach Advisory
- AT&T — Customer Data Breach Disclosure
- BleepingComputer — Snowflake Breach Coverage
- KrebsOnSecurity — Snowflake Investigation
- The Record — ShinyHunters/UNC5537 Analysis
- MITRE ATT&CK — Valid Accounts: Cloud (T1078.004)
- MITRE ATT&CK — Spearphishing Voice (T1566.004)
- Flashpoint — ShinyHunters Profile
- DataBreaches.net — ShinyHunters Tracking
- Microsoft — Entra ID Security
Threats related to ShinyHunters Extortion Campaign
- ShinyHunters-Branded Extortion Campaign Expands with Vishing & SSO Attacks
- ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypass
- ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering
- ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift Supply-Chain Compromise Targeting Salesforce Environments
- Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns
- Vercel April 2026 Security Incident — Context.ai OAuth Compromise Leads to Google Workspace Takeover and Customer Environment Variable Exposure
Detection coverage for TL-2026-0030
As of 2026-02-02, Threadlinqs Intelligence publishes 13 detection rule(s) for TL-2026-0030 across Splunk SPL, Microsoft KQL and Sigma, covering 63 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.