Trending
ee-track">
Link copied!

Table of Contents

ShinyHunters, Threat Actor Profiles,

Threat Actor Profile: ShinyHunters

ShinyHunters is a financially motivated data-theft and extortion collective that steals data from SaaS, cloud, and enterprise platforms and pressures victims to pay by threatening to publish it, rather than by encrypting their systems. According to the FBI, ShinyHunters and its associated operators have compromised more than 140 organizations since 2025 and obtained at least $70 million in extortion payments.

The ShinyHunters threat actor has been publicly active since 2020 and has evolved from a data-broker operation selling breached databases on criminal forums into one of the most disruptive extortion brands in cybercrime. Its recent campaigns rely less on malware than on identity: voice phishing (vishing) to capture single sign-on credentials and MFA codes, malicious OAuth applications, stolen integration tokens, and mass-scanning of misconfigured SaaS tenants. In 2026 the group added application exploitation, including a zero-day in Oracle PeopleSoft, to that playbook.

“ShinyHunters” does not map cleanly to a single team. It is a brand associated with The Com, an English-speaking cybercrime community, and since August 2025 it has overlapped with Scattered Spider and LAPSUS$ under the banner “Scattered LAPSUS$ Hunters.” Google Threat Intelligence Group (GTIG) tracks ShinyHunters-branded activity across several linked clusters, and the name can also be borrowed by unrelated actors, which makes attribution of any individual incident dependent on incident-specific evidence rather than leak-site branding alone.

Quick facts: ShinyHunters at a glance

  • Active since: 2020 under the ShinyHunters name (group states it previously operated as “GnosticPlayers”); MITRE assesses activity since at least 2019
  • Operating model: Loose collective of overlapping clusters; data theft followed by pay-or-leak extortion
  • FBI-reported impact: 140+ organizations compromised since 2025; at least $70 million in extortion payments
  • Primary access methods: Vishing for SSO credentials and MFA codes, OAuth app and token abuse, SaaS misconfigurations, application exploits
  • Tracked as: UNC6240, UNC6661, UNC6671, UNC6040 (Google); Bling Libra; MITRE G1057
  • Most recent major event: Claimed breach of the FBI’s FBIJobs.gov applicant portal (September 22, 2026); alleged leader arrested in the Netherlands (announced September 29, 2026)

Origin, Targets, and Global Reach

ShinyHunters emerged in spring 2020, when actors using the name claimed the theft of more than 100 million records from Indonesian e-commerce platform Tokopedia, Indian edtech firm Unacademy, and others within a span of weeks, selling the databases on criminal forums. In public statements in September 2026, group representatives said they originally operated as “GnosticPlayers” before rebranding to ShinyHunters in 2020. During this first data-broker era, the group’s methods were comparatively simple: credential phishing, exposed cloud storage, and secrets left in company code repositories.

Law enforcement pressure has been constant but has not ended the brand. French national Sébastien Raoult was arrested in Morocco in 2022, extradited to the United States, and sentenced to three years in prison. In June 2025, French authorities arrested four people connected to the BreachForums ecosystem, one reportedly using the ShinyHunters handle, though researchers and the group indicated those arrested were affiliates rather than core leadership. Activity continued without interruption.

ShinyHunters’ targeting is broad and platform-driven rather than tied to a single sector: instead of attacking organizations one at a time, it finds a weakness in a platform that thousands of companies share, automates exploitation across customers, and extorts the results. Reported victims span technology, retail, financial services, healthcare, education, telecommunications, and government. The FBI describes the group as linked to cyberattacks in the United States, the Netherlands, and around the world.

Platforms abused in documented ShinyHunters-branded campaigns include:

  • Salesforce (vishing-driven malicious connected apps, Experience Cloud guest-profile misconfigurations)
  • Okta, Microsoft Entra, Microsoft 365, and Google Workspace (SSO and MFA compromise)
  • DocuSign and Snowflake (credential and token abuse)
  • Oracle PeopleSoft (zero-day exploitation, CVE-2026-35273)
  • Instructure Canvas (application flaws in the learning management system)

Representative 2026 victims and claims, which range from confirmed incidents to unverified leak-site assertions, include:

  • Instructure (Canvas): Confirmed data exfiltration affecting a platform used by thousands of institutions; the group claimed data on roughly 275 million people across nearly 9,000 schools.
  • Oracle PeopleSoft customers: More than 100 organizations were notified of potentially vulnerable endpoints, 68% of them in higher education; the University of Nottingham confirmed a breach.
  • Healthcare: Health-ISAC warned in July 2026 of an increase in successful ShinyHunters attacks on the sector. DentaQuest disclosed an incident affecting 15 million individuals in a regulatory filing that does not name an attacker; ShinyHunters claimed it and published data.
  • Consumer brands and telecom: A dataset attributed to Carhartt (12.9 million email addresses, per Have I Been Pwned, not publicly confirmed by the company), a limited breach confirmed by Kodak, and a breach of Dutch telecom provider Odido.
  • Government: Florida’s motor vehicle agency investigated a breach of its DAVID driver database that ShinyHunters claimed (200,000+ records, unconfirmed), which the agency attributed to credentials a police employee stored on a personal device; and the claimed FBIJobs.gov breach described below.

Leak-site listings and branding are unverified claims until corroborated by victim disclosures, regulatory filings, or law enforcement.

Operational Capabilities

ShinyHunters-branded operations combine social engineering, identity abuse, and opportunistic exploitation, scaled across many victims at once. Key characteristics include:

  • Voice Phishing at Scale – Operators call employees posing as IT support, direct them to look-alike SSO pages to capture passwords and MFA codes in real time, or impersonate employees to the real help desk to reset credentials or enroll new devices. Since May 2026, some operators have contacted employees on personal phones using urgent passkey enrollment as a pretext.
  • OAuth and Token Abuse – In the Salesforce campaign, victims were walked through authorizing a malicious connected app, often a modified copy of Data Loader disguised under a plausible name. Stolen OAuth and authentication tokens from third-party integrations (Salesloft Drift, Gainsight, Anodot) have given access to customer environments without a fresh sign-in or MFA prompt.
  • Mass Scanning of Misconfigurations – The group scanned Salesforce Experience Cloud sites for over-permissive guest profiles using a modified version of an open-source auditing utility, affecting an estimated 300 to 400 organizations. Salesforce characterized this as a configuration issue rather than a platform vulnerability.
  • Application Exploitation – ShinyHunters has moved beyond social engineering, exploiting cross-site scripting flaws in Canvas, a zero-day in Oracle PeopleSoft’s Environment Management component, and an unauthenticated file-upload bug in the content management system running Clop’s leak site.
  • Cluster-Based Operating Model – GTIG attributes intrusion and extortion phases to different clusters in some campaigns (for example, UNC6040/UNC6661 intrusions followed by UNC6240 extortion) and to the same cluster in others. The Scattered LAPSUS$ Hunters Telegram channels have also solicited insiders at target companies.
  • Pressure-Driven Extortion – Ransom emails itemize stolen data, provide a Bitcoin address, and set 72-hour deadlines, with proof samples posted on public file-sharing sites and negotiations conducted over Tox. Pressure extends to harassment of victims and their families, swatting, DDoS attacks, and defacement.
  • Encryptor in Development – A ransomware-as-a-service encryptor, ShinySp1d3r, has been under development since late 2025, but no real-world deployment has been documented. Actors in this orbit have previously deployed other operators’ encryptors, so encryption remains a possibility to plan for rather than an observed norm.

Recent Activity

ShinyHunters’ 2026 campaign calendar has been unusually dense. In late April 2026, the group breached Instructure, the company behind the Canvas learning management system, claimed responsibility on May 3, and set a deadline. After Instructure attempted to patch rather than negotiate, the group re-entered on May 7 through a second, unpatched flaw, defaced roughly 300 school login portals with a ransom note, and took Canvas offline at many institutions during end-of-year exams. Instructure reached an agreement with the actor on May 11; the CEO described a return of the data with digital confirmation of destruction, while multiple outlets characterized the arrangement as a ransom payment. The terms were not disclosed.

On May 15, 2026, the FBI issued a public service announcement about ShinyHunters following the Canvas attack, warning that the group uses harassment, threats against victims’ families, and in some cases swatting, and may exaggerate its access to personal information. Between May 27 and June 9, the group exploited Oracle PeopleSoft before the vendor’s June 10 advisory, a zero-day campaign GTIG attributes to UNC6240 that touched roughly 300 instances at more than 100 organizations. Healthcare and consumer-brand incidents followed through July and August.

In September, the group turned on other targets of its own. On September 18, ShinyHunters defaced the dark web leak site of the rival Clop ransomware gang, exploiting an unauthenticated upload flaw in the Grav CMS and later claiming source code, logs, and private keys, claims that remain unverified; the feud traces back to the group publishing a working exploit for Clop’s Oracle E-Business Suite zero-day in October 2025.

On September 22, the group defaced FBIJobs.gov and claimed to have exfiltrated 2 to 3 TB of data on FBI employees and applicants, saying the attack was a response to the May advisory and giving the bureau one week to retract it. The FBI said it was investigating and that the point of breach was undetermined. Reuters matched names and addresses in a sample against credit-bureau and breached-data records in nine to ten cases, but could not establish whether the data came from FBI internal systems. The group later said it had achieved its goal and told NBC News that it would not publish the data it had stolen from the agency.

On September 29, the FBI and Dutch National Police announced the arrest of a 24-year-old Amsterdam man, detained on September 15, whom the FBI described as one of ShinyHunters’ alleged leaders. FBI Cyber Division Assistant Director Brett Leatherman used the announcement to publicly urge remaining members to turn themselves in, and Dutch police said further arrests have not been ruled out. The suspect is also suspected of attempted solicitation of two murders, according to Dutch police. ShinyHunters publicly denied that the man had any association with the group, and Dutch police clarified that the arrest was unrelated to the investigation into the Odido breach.

Tactics, Techniques, and Procedures (TTPs)

ShinyHunters-branded incidents have used different entry points, so the lifecycle below reflects behaviors documented across separate campaigns rather than steps present in every intrusion.

Initial access through identity. An operator calls an employee posing as IT support, claiming MFA settings are being updated, and sends them to a look-alike sign-in page (for example, a lookalike of a company SSO or Okta domain) that captures the password and MFA code, or tricks them into approving a push prompt. Variants include impersonating the employee to the legitimate help desk, passkey-enrollment lures delivered to personal phones, and device-code flows in which the employee approves an attacker-controlled client. In the Salesforce variant, the caller walks the victim to the connected-app setup page and reads out a connection code that links a modified Data Loader, registered through trial or compromised accounts, to the victim’s tenant.

Initial access through integrations and exposed applications. Stolen tokens issued to third-party integrations allow access without interactive sign-in. Over-permissive Salesforce Experience Cloud guest profiles allow CRM objects to be queried anonymously through the Aura endpoint. Canvas was breached via an XSS payload in a support ticket that yielded an authorization token and, later, a second XSS in the discussion feature. PeopleSoft activity targeted Environment Management Hub endpoints, using percent-encoded URL variations to bypass front-end protections before dropping JSP web shells.

Persistence and evasion. In a January 2026 vishing wave, operators registered their own MFA devices on compromised accounts and, in at least one case, used a Google Workspace add-on to permanently delete the Okta “security method enrolled” notification. A malicious Salesforce connected app persists as its own OAuth grant independent of the employee’s session. In the PeopleSoft campaign, operators deployed MeshCentral agents disguised as Azure services. Operators also used commercial VPNs and residential proxies to blend into normal traffic.

Discovery and lateral movement. From a compromised SSO session, operators search SharePoint and other cloud applications for terms such as “poc,” “confidential,” “internal,” “proposal,” “salesforce,” and “vpn,” and mine stolen data for secrets such as AWS keys and Snowflake tokens to extend access. In identity-led intrusions, movement is between applications rather than hosts: new sessions, OAuth grants, and unusual API calls in identity and SaaS logs, not process trees or beacons. The PeopleSoft campaign is the exception, using an SSH-spraying script and MeshCentral for host-to-host movement.

Exfiltration and extortion. Data is exported through Salesforce Data Loader or custom Python scripts calling the API (sometimes after small test queries), and through SharePoint and OneDrive downloads. Extortion demands can arrive days to months after initial access. After the January 2026 intrusions, UNC6240 sent emails listing stolen data, a Bitcoin address, and a 72-hour deadline. Stolen-data disclosure is the primary leverage; no file encryption has been reported in the SaaS incidents covered here.

Conclusion

ShinyHunters has turned a decentralized, identity-first approach into a repeatable extortion business: in under two years the FBI attributes more than 140 compromised organizations and at least $70 million in payments to the group and its associated operators. Its distinguishing feature is not sophisticated malware but its willingness to target shared platforms, such as Salesforce tenants, Canvas, and PeopleSoft, where one weakness yields hundreds of victims, and to escalate with harassment and public humiliation when victims resist.

The events of September 2026, including the claimed FBI breach, the attack on Clop, and an alleged leader’s arrest, show a group that is both under unusual pressure and still operating at high tempo. Arrests have repeatedly failed to end the brand, and because “ShinyHunters” is a collective of overlapping clusters that others can also borrow, organizations should expect continued vishing, token abuse, and application exploitation under this name regardless of what happens to any single individual.

Mitigations and Recommendations

  • Enforce phishing-resistant MFA (FIDO2 security keys or passkeys) without weaker fallback methods, so a stolen password and one-time code cannot be replayed through look-alike sign-in pages.
  • Require high-assurance, manual identity verification at the help desk for password resets, MFA changes, and new device enrollment, and brief staff on unsolicited “IT” calls with a verified callback procedure.
  • Alert on new MFA-factor or device enrollment, and preserve security notifications and audit logs outside user mailboxes.
  • Limit third-party integration permissions, require administrator approval for new Salesforce connected apps, and review connected apps and OAuth grants regularly.
  • Review Salesforce Experience Cloud guest-profile permissions; disable guest API access where unnecessary and restrict guests to data intended to be public.
  • Apply device trust and conditional access on SSO without legacy exceptions, and block device-code and authentication-transfer flows in Microsoft Entra unless there is a documented business need.
  • After any SaaS vendor breach disclosure, rotate API keys, OAuth tokens, and SSO credentials immediately rather than waiting to be notified.
  • Disable the PeopleSoft Environment Management Hub where feasible; otherwise block external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector and apply Oracle’s CVE-2026-35273 remediation.
  • Deploy secrets scanning and DLP on CRM records and support tickets, since stolen data is mined for keys to the next platform.
  • Export and retain identity and SaaS logs (Okta, Entra, Salesforce, Microsoft 365, Google Workspace) before default retention windows expire.
  • Prepare employees and executives for harassment, threatening calls to family members, and swatting, and establish a line to local law enforcement and DDoS mitigation in advance.
  • Follow FBI guidance: do not send payment or respond to extortion demands, and report incidents to the FBI. Evaluate any payment decision only with legal counsel and an incident response team, since payment cannot verify deletion of stolen data.

MITRE ATT&CK Techniques Associated with ShinyHunters

  • Reconnaissance (TA0043) – Phishing for Information: Spearphishing Voice (T1598.004): Vishing calls impersonating IT support to obtain credentials and MFA codes.
  • Resource Development (TA0042) – Acquire Infrastructure: Domains (T1583.001): Registers look-alike SSO and login domains.
  • Resource Development (TA0042) – Establish Accounts: Email Accounts (T1585.002): Creates email accounts for extortion and infrastructure.
  • Initial Access (TA0001) – Valid Accounts: Cloud Accounts (T1078.004): Uses stolen SSO and cloud credentials.
  • Initial Access (TA0001) – Exploit Public-Facing Application (T1190): Exploits PeopleSoft, Canvas, and web application flaws.
  • Execution (TA0002) – Command and Scripting Interpreter: JavaScript (T1059.007): Delivers XSS payloads, as in the Canvas intrusion.
  • Persistence (TA0003) – Cloud Application Integration (T1671): Malicious connected apps persist as independent OAuth grants.
  • Stealth (formerly Defense Evasion) – Masquerading: Match Legitimate Resource Name or Location (T1036.005): Disguises connected apps and MeshCentral agents under plausible names.
  • Credential Access (TA0006) – Steal Application Access Token (T1528): Abuses stolen OAuth and integration tokens.
  • Credential Access (TA0006) – Brute Force (T1110): Sprays common credentials, including SSH credentials in the PeopleSoft campaign.
  • Discovery (TA0007) – Remote System Discovery (T1018): Identifies internal hosts for onward movement.
  • Discovery (TA0007) – File and Directory Discovery (T1083): Searches cloud storage for sensitive keywords.
  • Lateral Movement (TA0008) – Use Alternate Authentication Material: Application Access Token (T1550.001): Pivots between SaaS applications using tokens.
  • Collection (TA0009) – Data from Information Repositories: Customer Relationship Management Software (T1213.004): Bulk-exports Salesforce CRM data.
  • Command and Control (TA0011) – Remote Access Tools (T1219): Uses MeshCentral and ConnectWise for remote control.
  • Exfiltration (TA0010) – Automated Exfiltration (T1020): Scripted, API-driven bulk data export.
  • Exfiltration (TA0010) – Exfiltration Over Web Service (T1567): Moves stolen data out through cloud and web services.
  • Impact (TA0040) – Defacement: Internal Defacement (T1491.001): Defaces login pages, as in the Canvas incident.
  • Impact (TA0040) – Financial Theft (T1657): Extorts victims for payment under threat of data publication.

Note: This mapping reflects TTPs documented in MITRE’s ShinyHunters group profile (G1057) and open-source incident analysis across separate campaigns; it is not an official MITRE-published mapping for every ShinyHunters-branded incident. Encryption-related techniques (T1486, T1490) apply only to the ShinySp1d3r development build, which has no documented deployment, and are therefore not listed.

Indicators of Compromise (IOCs)

These indicators come from separate campaigns. Corroborate addresses, app names, and extortion contacts with logs before treating them as proof of compromise or attribution.

Network (PeopleSoft campaign)

  • 142.11.200[.]186 – 142.11.200[.]190 (PeopleSoft attacker staging servers)
  • azurenetfiles[.]net (MeshCentral C2, spoofing Azure NetApp Files)
  • 176.120.22[.]24 (leak-site mirror contacted from attacker staging infrastructure; attribution context, not a victim-side IOC)

File Hashes (SHA-256)

  • meshagent32-azure-ops.exe: c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f
  • meshagent64-azure-ops.exe: f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc
  • meshagent64-v2.exe: d83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f
  • ShinySp1d3r development build: 3bf53cddf7eb98d9cb94f9aa9f36c211a464e2c1b278f091d6026003050281de

Host Artifacts

  • README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT (extortion marker on PeopleSoft hosts)
  • [victim_abbreviation]_fanout.sh (SSH-spray script)
  • Unexpected *.jsp files under PSEMHUB.war (possible web shells)
  • wipe-<random>.tmp files and SPDR … ENDS file headers (ShinySp1d3r development build only)

Tools and Extortion Contacts

  • ToogleBox Recall (Google Workspace add-on used to delete Okta enrollment notification emails)
  • shinycorp@tutanota[.]com, shinygroup@onionmail[.]com, shinycorp@tuta[.]com, shinygroup@tuta[.]com (extortion contact addresses)

Frequently Asked Questions

What is ShinyHunters?

ShinyHunters is a financially motivated data-theft and extortion collective active since 2020. It steals data from SaaS, cloud, and enterprise platforms and demands payment to keep it from being published. The FBI says it has compromised more than 140 organizations since 2025 and obtained at least $70 million in extortion payments.

Who is behind ShinyHunters, and what is UNC6240?

ShinyHunters is a loose collective associated with The Com and overlapping with Scattered Spider and LAPSUS$ as “Scattered LAPSUS$ Hunters.” Google tracks ShinyHunters-branded activity across linked clusters including UNC6240 (extortion), UNC6661, and UNC6671, and the name can be borrowed by unrelated actors.

Is ShinyHunters ransomware?

Not in the typical sense. In the SaaS incidents documented so far, the group steals data and extorts victims with the threat of publication, without encrypting files. An encryptor called ShinySp1d3r has been in development, but no real-world deployment has been documented as of October 2026.

How does ShinyHunters gain initial access?

Primarily through voice phishing that captures SSO credentials and MFA codes or tricks employees into authorizing malicious OAuth apps. The group also uses stolen integration tokens, misconfigured Salesforce Experience Cloud guest access, and application exploits, including an Oracle PeopleSoft zero-day (CVE-2026-35273).

Did ShinyHunters hack the FBI?

ShinyHunters claimed on September 22, 2026 to have breached FBIJobs.gov and stolen 2 to 3 TB of data. The FBI said it was investigating and that the point of breach was undetermined. Reuters matched sample data to real individuals in several cases but could not establish that it came from FBI internal systems.

Has anyone from ShinyHunters been arrested?

On September 29, 2026, the FBI and Dutch National Police announced the arrest of a 24-year-old Amsterdam man, detained September 15, as one of the group’s alleged leaders. ShinyHunters denies he was a member. Earlier arrests include Sébastien Raoult (sentenced to three years) and four people detained in France in June 2025.

Which industries and platforms does ShinyHunters target?

Reported victims span technology, retail, financial services, healthcare, education, telecommunications, and government. Platforms abused include Salesforce, Okta, Microsoft Entra, Microsoft 365, Google Workspace, DocuSign, Snowflake, Oracle PeopleSoft, and Instructure Canvas.

How can organizations defend against ShinyHunters?

Priority actions include phishing-resistant MFA, strict help desk identity verification, alerting on new MFA enrollment, restricting connected apps, auditing Salesforce guest permissions, rotating tokens after vendor breaches, and removing PeopleSoft’s Environment Management Hub from the internet. See Mitigations and Recommendations for the full list.

References

  • FBI, ShinyHunters: Cyber Criminal Group Attacks Learning Management System (PSA), May 15, 2026
  • BleepingComputer, FBI tells ShinyHunters members to turn themselves in after recent arrest, September 29, 2026
  • NBC News, FBI sends warning to cybercrime group that hacked it after Dutch arrest of ‘leader’, September 2026
  • Nextgov/FCW, ShinyHunters claims FBI data theft, demands bureau retract cyber warning, September 2026
  • Cyberpress, FBI and Dutch Police Arrest Alleged ShinyHunters Leader Linked to 140 Cyberattacks, September 2026
  • Proven Data, ShinyHunters: Attack Lifecycle, IOCs, and Incident Response Guide, September 28, 2026
  • CybelAngel, ShinyHunters: 8 Things We Know About the Group That Hacked Clop, September 22, 2026
  • Google Cloud Threat Intelligence, Voice Phishing Data Extortion (UNC6040/UNC6240)
  • MITRE ATT&CK, ShinyHunters (G1057)
  • Wikipedia, 2026 Canvas data breach

Media Disclaimer: This profile was compiled from publicly available government statements, open-source security reporting, and news coverage. Victim listings and breach claims made by threat actors are unverified unless corroborated by victim disclosures, regulatory filings, or law enforcement. It is provided for reference purposes only; readers bear full responsibility for their reliance on it.

Discover how we help proactively defend against evolving threats with Gen 3 intelligence. Request a Demo today!

Share Post:

Stay Informed

The Cyber Briefing Security Teams Actually Read!

Join security teams across 50+ countries getting Cyble's weekly research, advisories, and analyst insights.

No spam, ever. Unsubscribe anytime.

Related Topics

Scroll to Top

BOOK YOUR SESSION

Request A Personalized Demo

See how Cyble's threat intelligence protects your organization. A specialist will reach out within one business day.

Cyble may send me product updates, newsletters, event invitations, webinars, and other promotional communications. I may withdraw my consent at any time.

For information about Cyble's privacy practices, please review our Privacy Notice. You can withdraw your consent by using the contact methods described in the Privacy Notice or by raising a Rights Request.

Download the brochure

Get the Cyble Vision Brochure

Explore how Cyble Vision delivers AI-powered threat intelligence across your attack surface. Fill in your details to access the brochure.

Select one or more

Cyble may send me product updates, newsletters, event invitations, webinars, and other promotional communications. I may withdraw my consent at any time.

For information about Cyble's privacy practices, please review our Privacy Notice. You can withdraw your consent by using the contact methods described in the Privacy Notice or by raising a Rights Request.