ShinyHunters

Last updated

ShinyHunters is a black-hat criminal hacker and extortion group that is believed to have formed in 2020 and is said to have been involved in a massively significant amount of data breaches. The group often extorts the company they've hacked, if the company does not pay the ransom the stolen information is often sold or leaked on the dark web. [1] [2]

Contents

Name and alias

The name of the group is believed to be derived from Shiny Pokémon, a mechanic in the Pokémon video game franchise where Pokémon have a rare chance of being encountered in an alternate, "shiny" color scheme; players who actively try to collect such Pokémon through in-game strategies are often referred to as "shiny hunters". [3] [4]

Notable data breaches

Snowflake data hacks

In 2024, The ShinyHunters cybercriminal group claimed to have hacked Snowflake-related customers including Ticketmaster, Santander Bank, Neiman Marcus, and many others. [52] The group was also responsible for publishing data stolen from Twilio and Truist Bank. [53]

Salesforce data hacks

In June 4, 2025, ShinyHunters was tied to a widespread data-theft campaign targeting Salesforce cloud customers, which Google’s Threat Intelligence team tracked as UNC6040. [54] The cybercriminal group working in conjunction with Scattered Spider [55] (now believed to be the same group) impersonated IT support staff and used voice phishing (vishing) calls to trick employees into installing a malicious version of Salesforce's Data Loader tool, allowing them to access and extract sensitive customer data. Following the successful intrusions, Google's Threat Intelligence team notes the victims of these intrusions receive an extortion or ransom email from the ShinyHunters cybercriminal group, which is also tracked as UNC6240. [56]

This low-tech social engineering approach led to breaches at major companies including Google, Cisco, Adidas, Qantas, Allianz Life, Farmers Insurance Group, Workday, Pandora, Chanel, TransUnion, LVMH subsidiaries, including but not limited to, Dior, Louis Vuitton, and Tiffany & Co. [57] It is believed that a lot more victims have been impacted from this campaign, public disclosures are still impending.

In August 28, 2025, a campaign tracked by Google Threat Intelligence (formerly Mandiant) as UNC6395 used OAuth/refresh tokens stolen from Salesloft's Drift integration to access numerous Salesforce customer orgs between August 8–18, 2025, systematically exporting CRM data and hunting for credentials (e.g., AWS access keys, passwords, Snowflake tokens). [58] Google told reporters it was aware of over 700 potentially impacted organizations. Public disclosures tied to this campaign include Cloudflare, Workiva, Zscaler, Tenable, CyberArk, Elastic, BeyondTrust, Proofpoint, JFrog, Rubrik, Cato Networks, and Palo Alto Networks, each confirming unauthorized access to data in their Salesforce environments following the Salesloft/Drift compromise. [59] The ShinyHunters cybercriminal group claimed responsibility to the press.

On September 17, 2025, BleepingComputer was able to confirm ShinyHunters was behind the UNC6395 campaign, the biggest SaaS compromise in history. [60] ShinyHunters told BleepingComputer that the threat actors used the TruffleHog security tool to scan the source code for secrets, which resulted in the finding of OAuth tokens for the Salesloft Drift and the Drift Email platforms. Using these stolen Drift OAuth tokens, ShinyHunters told BleepingComputer that the threat actors stole approximately 1.5 billion data records for 760 companies from the "Account", "Contact", "Case", "Opportunity", and "User" Salesforce object tables.

Other data breaches

The following are other hacks that have been credited to or allegedly done by ShinyHunters. The estimated impacts of user records affected are also given, if possible. [61] [62] [63]

Lawsuits

ShinyHunters group is under investigation by the FBI, the Indonesian police, and the Indian police for the Tokopedia breach. Tokopedia's CEO and founder also confirmed this claim via a statement on Twitter. [93] [94]

Minted company reported the group's hack to US federal law enforcement authorities; the investigation is underway. [95]

Administrative documents from California reveal how ShinyHunters' hack has led to Mammoth Media, the creator of the app Wishbone, getting hit with a class-action lawsuit. [96]

Animal Jam stated that they are preparing to report ShinyHunters to the FBI Cyber Task Force and notify all affected emails. They have also created a 'Data Breach Alert' on their site to answer questions related to the breach. [97]

BigBasket filed a First Information Report (FIR) on November 6, 2020, to the Bengaluru Police to investigate the incident. [98]

Dave also initiated an investigation against the group for the company's security breach. The investigation is ongoing and the company is coordinating with local law enforcement and the FBI. [99]

Wattpad stated that they reported the incident to law enforcement and engaged third-party security experts to assist them in an investigation. [100]

Following the ransomware attack on Jaguar and Land Rover, which M&S hackers claimed responsibility for as first reported by the Telegraph [101] , also linked to the groups Scattered Spider and ShinyHunters, the National Cyber Security Centre, part of GCHQ, is understood to be monitoring the situation.

Arrests

In May 2022, Sébastien Raoult, a French programmer suspected of belonging to the group, was arrested in Morocco and extradited to the United States. He faced 20 to 116 years in prison. [102] [103]

In January 2024 Raoult was sentenced to three years in prison and ordered to return five million dollars. [104] Twelve months of the sentence are for conspiracy to commit wire fraud and the remainder for aggravated identity theft. [104] He will face 36 months of supervised release afterwards. [104] Raoult had worked for the group for more than two years according to the US Attorney's Office for the Western District of Washington, but was not a major player within the group. [104]

In May–June 2025, U.S. prosecutors in the District of Massachusetts charged Matthew D. Lane, a 19-year-old Massachusetts student, with hacking and extorting an education-technology provider widely reported to be PowerSchool; prosecutors said Lane used stolen contractor credentials to access the company's network in 2024, exfiltrate data on tens of millions of students and teachers, and demand a $2.85 million bitcoin ransom. Lane agreed to plead guilty on May 20, 2025, and entered a guilty plea on June 6, 2025. [105] [106] Although some re-extortion emails sent to North Carolina school authorities in early May 2025 opened with "Hello, we are ShinyHunters". [107]

On June 25, 2025, French authorities announced that four members of the ShinyHunters cybercriminal group were arrested in multiple French regions for cybercrime activities. The coordinated global law enforcement effort targeting the 'ShinyHunters', 'Hollow', 'Noct', and 'Depressed' personas. [108] It is believed that the French have arrested an affiliate of ShinyHunters cybercriminal group and not the ring leader of the ShinyHunters cybercriminal group as they are still wreaking havoc in the cybersecurity world. [109] [110]

References

  1. 1 2 "ShinyHunters Is a Hacking Group on a Data Breach Spree". Wired. ISSN   1059-1028 . Retrieved 2021-01-25.
  2. Cimpanu, Catalin. "A hacker group is selling more than 100 billion user records on the dark web". ZDNet. Retrieved 2021-01-25.
  3. King, Ashley (2024-06-19). "More Details Emerge on Ticketmaster Breach Affecting 500M+". Digital Music News. Retrieved 2025-01-19.
  4. Frank, Allegra (2016-12-02). "Why Pokémon players spend hours and hours chasing shiny monsters". Polygon . Archived from the original on 2024-04-17. Retrieved 2024-12-23.
  5. Cimpanu, Catalin (2020-05-22). "25 million user records leak online from popular math app Mathway". ZDNET . Retrieved 2025-04-18.
  6. Cimpanu, Catalin. "Hacker leaks 40 million user records from popular Wishbone app". ZDNet. Retrieved 2021-01-25.
  7. "Microsoft's GitHub account breached by threat actors Shiny Hunters". TechGenix. May 21, 2020.
  8. "'Shiny Hunters' bursts onto dark web scene following spate of breaches". SC Media. May 8, 2020.
  9. "Microsoft's GitHub account hacked, private repositories stolen". BleepingComputer.
  10. Deschamps, Tara (2020-07-21). "Wattpad storytelling platform says hackers had access to user email addresses". CTVNews. Retrieved 2021-01-25.
  11. "Wattpad warns of data breach that stole user info | CBC News". CBC. Retrieved 2021-01-25.
  12. "Wattpad data breach exposes account info for millions of users". BleepingComputer. Retrieved 2021-01-25.
  13. "ShinyHunters hacked Pluto TV service, 3.2M accounts exposed". Security Affairs. 2020-11-15. Retrieved 2021-01-25.
  14. "3 Million Pluto TV Users' Data Was Hacked, But the Company Isn't Telling Them". Vice.com. 4 December 2020. Retrieved 2021-01-25.
  15. Whittaker, Zack (16 November 2020). "Animal Jam was hacked, and data stolen; here's what parents need to know". TechCrunch. Retrieved 2021-01-25.
  16. Abrams, Lawrence (2020-11-11). "Animal Jam kids' virtual world hit by data breach, impacts 46M accounts". BleepingComputer. Retrieved 2021-01-25.
  17. "ShinyHunters hacker leaks 5.22GB worth of Mashable.com database". 5 November 2020. Retrieved 27 May 2023.
  18. "A Notorious Hacker Gang Claims to Be Selling Data on 70 Million AT&T Subscribers". GIzmodo. 21 August 2021. Retrieved 26 August 2023.
  19. "AT&T finally acknowledged the data breach". Bleeping Computer. Retrieved 26 August 2023.
  20. "AT&T acknowledges data breach affecting 51 million people - Panda Security". 12 April 2024.
  21. "Hacker leaks 1.9 million user records of photo editing app Pixlr". The Tribune . 2021-01-21. Retrieved 2021-01-25.
  22. "Hacker leaks full database of 77 million Nitro PDF user records". BleepingComputer. Retrieved 2021-01-25.
  23. "Bonobos clothing store suffers a data breach, hacker leaks 70GB database". BleepingComputer. Retrieved 2021-01-25.
  24. "Bonobos clothing store suffers a data breach, hacker leaks 70GB database". RestorePrivacy. 11 January 2022. Retrieved 2022-01-11.
  25. Zetter, Kim. "AT&T Paid a Hacker $370,000 to Delete Stolen Phone Records". Wired. ISSN   1059-1028 . Retrieved 2024-08-04.
  26. "All Santander staff and millions of customers have data hacked". bbc.com. 2 June 2024. Retrieved 2024-07-22.
  27. Zetter, Kim. "Hackers Detail How They Allegedly Stole Ticketmaster Data From Snowflake". Wired. ISSN   1059-1028 . Retrieved 2024-07-22.
  28. Rundle, James (2025-05-07). "PowerSchool Paid Ransom to Hackers After Breach". Wall Street Journal. ISSN   0099-9660 . Retrieved 2025-09-08.
  29. Coker, James (2025-05-09). "PowerSchool Admits Ransom Payment Amid Fresh Extortion Demands". Infosecurity Magazine. Retrieved 2025-09-08.
  30. Gatlan, Sergiu. "Texas sues PowerSchool over breach exposing 62M students, 880k Texans". BleepingComputer. Retrieved 2025-09-08.
  31. "Legal Aid Agency cyber security incident: frequently asked questions". GOV.UK. 2025-09-04. Retrieved 2025-09-08.
  32. "FalconFeeds.io Blog | Latest Cyber Threat Intelligence & Security Insights". falconfeeds.io. Retrieved 2025-09-08.
  33. Croft, Daniel (2025-08-13). "ShinyHunters forms hacking supergroup with Scattered Spider, teases major leaks". cyberdaily.au. Retrieved 2025-09-08.
  34. Moloney, Charlie. "'Hackers' threaten to publish Legal Aid Agency records". Law Gazette. Retrieved 2025-09-08.
  35. Sellman, Mark (2025-08-11). "Hackers threaten to publish legal aid files unless member is freed". thetimes.com. Retrieved 2025-09-08.
  36. "Access Restricted". telegraph.co.uk. Retrieved 2025-09-08.
  37. "Scattered Spider has a new Telegram channel to list its attacks". DataBreaches.Net. 2025-08-09. Retrieved 2025-09-08.
  38. Abrams, Lawrence. "ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH". BleepingComputer. Retrieved 2025-09-08.
  39. Abrams, Lawrence. "ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH". BleepingComputer. Retrieved 2025-09-08.
  40. "The Cost of a Call: From Voice Phishing to Data Extortion". Google Cloud Blog. Retrieved 2025-09-08.
  41. "The Cost of a Call: From Voice Phishing to Data Extortion". Google Cloud Blog. Retrieved 2025-09-08.
  42. "Are Scattered Spider and ShinyHunters one group or two? And who did France arrest? (1)". DataBreaches.Net. 2025-08-03. Retrieved 2025-09-08.
  43. Kovacs, Eduard (2025-08-06). "Google Discloses Data Breach via Salesforce Hack". SecurityWeek. Retrieved 2025-08-10.
  44. Abrams, Lawrence. "Qantas confirms data breach impacts 5.7 million customers". BleepingComputer. Retrieved 2025-09-08.
  45. Abrams, Lawrence. "Qantas discloses cyberattack amid Scattered Spider aviation breaches". BleepingComputer. Retrieved 2025-09-08.
  46. Abrams, Lawrence. "ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH". BleepingComputer. Retrieved 2025-09-08.
  47. "Are Scattered Spider and ShinyHunters one group or two? And who did France arrest? (1)". DataBreaches.Net. 2025-08-03. Retrieved 2025-09-08.
  48. "Access Restricted". telegraph.co.uk. Retrieved 2025-09-08.
  49. "M&S hackers claim to be behind Jaguar Land Rover cyber attack". bbc.com. 2025-09-03. Retrieved 2025-09-08.
  50. Toulas, Bill. "Jaguar Land Rover says cyberattack 'severely disrupted' production". BleepingComputer. Retrieved 2025-09-08.
  51. "Statement on Cyber Incident | JLR Media Newsroom". media.jaguarlandrover.com. Retrieved 2025-09-08.
  52. Zetter, Kim (2024-06-17). "Hackers Detail How They Allegedly Stole Ticketmaster Data From Snowflake". Wired. ISSN   1059-1028 . Retrieved 2025-03-10.
  53. "ShinyHunters Leak What They Claim Are 33M Twilio Authy Phone Numbers, Neiman Marcus and Truist Bank Data". DataBreaches.Net. 2024-07-05. Retrieved 2025-09-08.
  54. "The Cost of a Call: From Voice Phishing to Data Extortion". Google Cloud Blog. Retrieved 2025-09-08.
  55. "Are Scattered Spider and ShinyHunters one group or two? And who did France arrest? (1)". DataBreaches.Net. 2025-08-03. Retrieved 2025-09-08.
  56. "The Cost of a Call: From Voice Phishing to Data Extortion". Google Cloud Blog. Retrieved 2025-09-08.
  57. Abrams, Lawrence. "ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH". BleepingComputer. Retrieved 2025-09-08.
  58. "Widespread Data Theft Targets Salesforce Instances via Salesloft Drift". Google Cloud Blog. Retrieved 2025-09-08.
  59. Gatlan, Sergiu. "SaaS giant Workiva discloses data breach after Salesforce attack". BleepingComputer. Retrieved 2025-09-08.
  60. Abrams, Lawrence. "ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks". BleepingComputer. Retrieved 2025-09-19.
  61. May 2020, Jitendra Soni 11 (11 May 2020). "ShinyHunters leak millions of user details". TechRadar. Retrieved 2021-01-25.{{cite web}}: CS1 maint: numeric names: authors list (link)
  62. July 2020, Nicholas Fearn 29 (29 July 2020). "386 million user records stolen in data breaches — and they're being given away for free". Tom's Guide. Retrieved 2021-01-25.{{cite web}}: CS1 maint: numeric names: authors list (link)
  63. ""Shiny Hunters" Hacker Group Keep 73 Mn User Records on Darknet". CISO MAG | Cyber Security Magazine. 2020-05-11. Retrieved 2021-01-25.
  64. "Amazon, Swiggy's payment processor hit by data breach". The Times of India. Retrieved 2021-01-05.
  65. 1 2 3 4 5 6 7 8 9 10 Cimpanu, Catalin. "A hacker group is selling more than 73 million user records on the dark web". ZDNet.
  66. "ShinyHunters Offers Stolen Data on Dark Web". Dark Reading. 28 July 2020. Retrieved 2021-01-25.
  67. 1 2 3 4 5 6 7 "ShinyHunters Offers Stolen Data on Dark Web". Dark Reading. 28 July 2020.
  68. 1 2 3 4 5 6 7 8 9 "ShinyHunters leaked over 386 million user records from 18 companies". Security Affairs. July 28, 2020.
  69. "Promo.com data breach impacts 23 million content creators". The Daily Swig | Cybersecurity news and views. July 28, 2020.
  70. Taylor, Charlie. "Irish start-up Glofox investigates possible data breach". The Irish Times. Retrieved 2021-01-25.
  71. Defense, Binary. "Shiny Hunters Group Selling Data Stolen From 11 Different Companies" . Retrieved 27 May 2023.
  72. "Shiny Hunters hackers try to sell a host of user records from breaches". MalwareTips Community. 8 May 2020.
  73. "ShinyHunters dump partial database of broker firm Upstox". hackread.com. 12 April 2021.
  74. "Indonesias Tokopedia probes alleged data leak of 91 mln users". reuters.com. 3 May 2020.
  75. "Wishbone Breach: 40 million Records Leaked on Dark Web". infosecurity-magazine.com. 22 May 2020.
  76. "Wattpad data breach exposes account info for millions of users". 14 July 2020.
  77. "Hacker shares 3.2 million Pluto TV accounts for free on forum". 14 Nov 2020.
  78. "Hacker leaks full database of 77 million Nitro PDF user records". 20 Jan 2021.
  79. "Bonobos clothing store suffers a data breach, hacker leaks 70GB database". 22 Jan 2021.
  80. "Hacker leaks 20 million alleged BigBasket user records for free". 25 April 2021.
  81. "AT&T says leaked data of 70 million people is not from its systems". 17 Mar 2024.
  82. "Data of 560 million Ticketmaster customers for sale after alleged breach". 30 May 2024.
  83. "ShinyHunters claims Santander breach, selling data for 30M customers". 31 May 2025.
  84. "Twilio Confirms Data Breach After Hackers Leak 33M Authy User Phone Numbers". 4 Jul 2024.
  85. "Neiman Marcus data breach: 31 million email addresses found exposed". 8 Jul 2024.
  86. "PowerSchool hacker claims they stole data of 62 million students". 22 Jan 2025.
  87. "Legal Aid Agency data breach bigger than originally thought: affects data as far back as 2007". 21 Aug 2025.
  88. "Qantas confirms data breach impacts 5.7 million customers". 9 Jul 2025.
  89. "Google confirms data breach exposed potential Google Ads customers' info". 9 Aug 2025.
  90. "Massive Allianz Life data breach impacts 1.1 million people". 19 Aug 2025.
  91. "Farmers Insurance data breach impacts 1.1M people after Salesforce attack". 25 Aug 2025.
  92. "TransUnion suffers data breach impacting over 4.4 million people". 28 Aug 2025.
  93. "Who are Shiny Hunters?". AndroidRookies. May 21, 2020.
  94. @UnderTheBreach (May 13, 2020). "Twitter post" (Tweet) via Twitter.[ dead link ]
  95. "Minted confirms data breach as Shiny Hunters sell its database". 29 May 2020.
  96. "Wishbone App Maker Mammoth Media Hit with Class Action Over Data Breach Affecting 40 Million Users". classaction.org. 4 June 2020.
  97. "Animal Jam kids' virtual world hit by data breach, impacts 46M accounts". BleepingComputer.
  98. "BigBasket, India's Leading Online Supermarket Shopping, Allegedly Breached. Personal details of over 20 million people sold in darkweb". cybleinc.com. 7 November 2020.
  99. "Security incident at Dave". A Banking Blog for Humans. July 25, 2020.
  100. "FAQs on the Recent Wattpad Security Incident". Help Center.
  101. "Access Restricted". telegraph.co.uk. Retrieved 2025-09-08.
  102. "Sébastien Raoult, Français incarcéré au Maroc, menacé d'extradition aux Etats-Unis où il risque une lourde peine". lemonde.fr (in French). August 3, 2022.
  103. "Cybercriminalité: Détenu aux Etats-Unis, le Français Sébastien Raoult espère toujours un "retour en France"". 31 May 2023.
  104. 1 2 3 4 Jones, Connor (2024-01-10). "ShinyHunters chief phisherman gets 3 years, must cough up $5M". The Register . Retrieved 2024-01-12.
  105. "District of Massachusetts | Worcester College Student to Plead Guilty to Cyber Extortions | United States Department of Justice". justice.gov. 2025-05-20. Retrieved 2025-09-08.
  106. Abrams, Lawrence. "PowerSchool hacker pleads guilty to student data extortion scheme". BleepingComputer. Retrieved 2025-09-08.
  107. "PowerSchool paid a hacker's extortion demand, but now school district clients are being extorted anyway (3)". DataBreaches.Net. 2025-05-07. Retrieved 2025-09-08.
  108. Franceschi-Bicchierai, Lorenzo (2025-06-26). "US, French authorities confirm arrest of BreachForums hackers". TechCrunch. Retrieved 2025-07-03.
  109. "Are Scattered Spider and ShinyHunters one group or two? And who did France arrest? (1)". DataBreaches.Net. 2025-08-03. Retrieved 2025-09-07.
  110. Abrams, Lawrence. "ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH". BleepingComputer. Retrieved 2025-09-08.