ZeroHour

shadowbyt3$

ransomware group · aka ShadowByt3, Shadow BYT3 · unknown (no public attribution located) · active since 2026-06-13 (first tracked leak-site post, per this dashboard)

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
0
All-time (tracked)
41since 2026-02-24
Last post
06-16 16:48UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

ShadowByt3 is a small data-theft and extortion operation first tracked by this dashboard on 2026-06-13, with 10 victims listed in a burst of posts between 2026-06-13 and 2026-06-16 and none since. Its victim set mixes high-profile brands (Nintendo, Starbucks, Syngenta's Cropwise) with smaller firms and even doxx-style posts targeting individuals, suggesting opportunistic rather than sector-focused targeting. Listed posts have included proof-of-access artifacts such as a Nintendo file tree rather than full data dumps, a pressure tactic common among extortion groups. A post referencing the return of BreachForums indicates ties to the breach-forum/data-trading community. Public attribution, ransom demands, and payment figures are unknown.

Tactics & tooling
  • Operates a dedicated leak site for victim announcements (10 victims posted in a ~3-day burst in June 2026).
  • Publishes proof-of-access artifacts such as directory/file listings (e.g., 'nintendo_file_tree.txt') instead of full dumps.
  • Posts doxx-style content naming individuals (e.g., 'Eric J Taylor Doxx').
  • Claims against widely recognized brands alongside smaller companies, indicating opportunistic targeting; access vectors unknown.
  • Targets HR/SaaS platform data (TinyPulse); whether access was direct or via a third party is unknown.
  • Posts commentary on the breach-forum ecosystem, suggesting ties to the data-trading community.
  • No publicly confirmed encryption or destructive events; activity appears data-theft focused, though extortion method details are unknown.
Targeted sectors
educationgamingfood and beveragehospitality softwareHR softwareagriculture technology
Notable public victims

Nintendo (file tree posted; claimed access via TinyPulse), Starbucks, Stride Learning, University of Georgia, Syngenta (Cropwise), TinyPulse, Hotelogix

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
TINYpulse NINTENDO BREACH (nintendo.com) · Jun 16, 2026This will be quick. You don't even want to read the private messages as some will be embarrasing. Some people are confused but this breach doesn't affect you unless if you use tinypulse and work for nintendo. There will be more victims coming soon. If you get a email by us. by us we mean are only email on are leak site, then respond or it will get leaked. We will send file trees for confirmation to prove we actually breached your company. It's pretty funny how companies are defending themselves and when the truth comes out now they want to stay quiet. We have no further questions to answer. This is a warning to all companies if you get breached by us, It's best to contact us especially if we show you the file size. This was true negligence and now you will likely face a massive lawsuit, have fun tinypulse and told you this would be quick. uncompressed file size: (856MB) compressed size: (6.89MB) The included data includes: - full name, first name, last name, email (the w9 is only one and multiple invoices) - Private Employee Chats: Direct internal messages and conversations between workers. - Mar 10, 2025 Sure, it's Knowledge Team—we've needed more content creators for years, but it seems all we can ever get approved are more associates, often temporarily. This helps some, and I know there are vague rumors that maybe we will be able to swap our associates over to NOA employees in the future, but that's not what we need—we need more writers so that we can distribute the primary work among more people. overworking chat: Sep 22, 2025 How happy are you at work? 3 I'm generally extremely content, but the overwhelming number of overlapping high-priority projects and a constant stream of meetings, has left me with little to no available occupancy. This has made it tough to manage everything effectively and still make time for innovation.
TinyPulse Nintendo (Nintendo.com) nintendo_file_tree.txt · Jun 14, 2026The breach has been confusing some people like they didn't breach nintendo and all that, But are goal wasn't beach nintendo directly but to steal some pii, operational plans, all private chats of employees. This Breach doesn't affect nintendo gaming wise it only affects a small amount of employees that work for nintendo and have used tinypulse. Tinypulse you have till june 16th 2026 to contact us via telegram or email that we have sent you. Nintendo decided to not pay so we are demanding that tinypulse pays or all data will be leaked including private messages on nintendo employees and not all employees are happy we can tell you that. Private messages are about to not become private if tinypulse doesn't reach an agreement with us. This is all we have to say about it no further questions. it's simple if they don't pay there leaked. This is just the file tree of all the data we stole so you can actually see that there are w9 forms with employee id's.
Stride Learning · Jun 13, 2026Stride Learning Should've Paid the ransom. We were only asking $500,000 in bitcoin or monero it's not that hard. This is a warning to all companies that if you don't pay it will get leaked. If you pay you have are word that it's deleted also with a picture before and after. If you want we will also take a video.
University Of Georgia · Jun 13, 2026ShadowByt3$ has breached University of Georgia. The full data is on are leak site. We stole approximately 3.2 MB in raw text files. No customers were affected just exployees the following was stolen. - Physical Locations: Home addresses (like the Columbus, GA residential home) and specific office numbers (like Office 2207). - Private Contact Info: Personal cell phone numbers and home phone numbers (e.g., the 404-736-xxxx). - Employee Information: This often includes full names, contact details, and institutional identification photos. - Project Documentation: Information regarding internal university projects, including tracking logs and administrative data for various departments. - Workforce Data: Internal metadata such as position numbers, departmental assignments, and work schedules. - Technical Details: Notes regarding system maintenance and development that could potentially highlight internal processes - Critical Infrastructure: Active project maps for GEMA (Emergency Management), Georgia Broadband, and GDOT (Transportation) through 2026. - Government Records: Access to Asset Forfeiture logs and County-level GIS (Athens-Clarke, Bibb) that underpins 911 dispatch and land taxes. - Leadership Secrets: The UGA Office of the President Mail Tracker and Gov360 anonymous executive coaching logs. - The "SME" Map: we have identified the "Subject Matter Experts" like Noah Abouhamdan, Chad Rupert, and Pat Russell. we know exactly how many hundreds of hours these people have spent on specific pieces of code. - Security Clearances: we know who is a "Benefited" full-time employee (high-value target) versus a "Student Assistant" (low-value entry point).
StarBucks Company (StarBucks.com · Jun 13, 2026StarBucks Failed to reach out to us and didn't pay even $500,000 when we know they can afford it. It's not even that much we were asking for. Since you didn't contact is no negotiations and this is now in the hands of cybercriminals. This is a warning to all companies if you see yourself posted here to reach us. This is the only ammount we have on are servers due to migrating dmca and ignore abuse infrastructure. They were breached on 04/01/2026 and they know they were breached because they closed the s3 bucket starbucks-prod.
Hotelogix Company (Hotelogix.com) · Jun 13, 2026Should've not messed with us Hotelogix. We gave you guys numerous times to reach back and proceed with payment but you decided to fuck around and you found out. Any company that contacts us because you had a warning or we leaked proof should look at what we got if your concerned then contact us for payment if everything matches up. It's that simple and don't think twice or it can lead to what happened with this company. Don't be like Hotelogix and wait till the last Minute. It's best to pay first to so you don't end up like these companies to name a few University Of Georgia, Hotelogix, starBucks, and more mega link conversations: https://mega.nz/file/mwAGQDaA#TX0wXzN2JmzehD1WxV234_QiHaK7AzSA1PumfWq_HCU
BreachForums is Back (breachforu.ms) · Jun 13, 2026This is not a leak just an announcement that will stay up for however long they want to extend the promotion. Some may have been wondering why there is a logo of BreachForums. There is a logo because we have made an agreement with the BreachForums link. It seems legit and DragonForce has also done a promotion for them. Since DragonForce promoted them we decided to promote them. There have been many clones but if other groups are on there then it should be legit. We have loved BreachForums since when it first started and we would do anything to bring it back. We will promote them for one month starting today unless if they agree to extend the promotion. Check them out, register, and if were on there you should be on there. We will take a risk together but looking so far it's legit and the BreachForums clones is a long long story that It would take forever for us to explain. BREACHFORUMS We are aware that our clearnet domain (breachforu.ms) has been suspended. In recent days, breachforums.rs and breachforu.ms were suspended due to competitor attacks. Yukari (Former ShinyHunters Member) sits at her desk every day, sending requests with compromised police emails to get our domains taken down. She must be having a full mental breakdown because BreachForums will never shut down. We are moving to a better domain TLD. breachforum.st will be our new primary domain, which will go live with a major update within 24 hours. We will also release our .su and other bulletproof TLD mirror sites soon. We are taking all necessary steps to ensure this won’t happen again. Nevertheless, we deeply regret these events and apologize for the inconvenience. We are also working on the ShinyHunters clearnet pay-or-leak website, which will launch today or within 24 to 48 hours. Our partnership with ShinyHunters and sponsorships will continue without interruption. BreachForums will keep growing stronger than ever. Nothing can stop us. Thank you for your patience. Join our Telegram…
Lead Company (Leadership Boulevard) · Jun 13, 2026Company Site: leadschool.in size: 765.9MB This is will be quick. The following schools are affected: The specific schools explicitly named in the exfiltrated folders include: - Arya Vidyapith - Aakarsh International Public School - Students High School - Rainbow International Matric Hr. Sec. School - Vignan Private School The following info was stolen: 1. Personally Identifiable Information (PII) of Students - Full Names and Demographics: Complete names of children sorted by gender and admission numbers. - Academic Progression: Exact tracking of student grade levels (e.g., SKG, Class 1, Class 2) and division assignments - Age and Vital Records: Exact dates of birth (DOB) for all enrolled students. - Physical Locations: Full residential addresses, cities/districts (such as Nampally, Telangana), and exact localized postal pincodes 2. Guardian and Parent Contact Registries - Parent Identity: Full names of both fathers and mothers linked directly to their children. - Direct Contact Methods: Active personal mobile numbers for parents, creating a severe vulnerability for automated spam or voice-phishing attacks. - Digital Contact: Parent email addresses intended for formal school updates. - Student Led Events - Teacher Certificates - gac-reports - Assessments 3. Proprietary LEAD School Academic Metrics - ELGA Placement Data: Internal academic tracking metrics, showing specific curriculum tiers like "ELGA Class" (e.g., ELGA02, ELGA06) and "ELGA Division" for individual students. - Classroom Analytics: Operational performance data exfiltrated directly from the nucleus.leadschool.in administrative portal. - Teacher Resources: Lesson plans, training modules, and classroom resources that form the core commercial assets of the LEAD platform.
Cropwise (Syngenta Group) · Jun 13, 2026Company Site: leadschool.in size: 765.9MB This is will be quick. The following schools are affected: The specific schools explicitly named in the exfiltrated folders include: - Arya Vidyapith - Aakarsh International Public School - Students High School - Rainbow International Matric Hr. Sec. School - Vignan Private School The following info was stolen: 1. Personally Identifiable Information (PII) of Students - Full Names and Demographics: Complete names of children sorted by gender and admission numbers. - Academic Progression: Exact tracking of student grade levels (e.g., SKG, Class 1, Class 2) and division assignments - Age and Vital Records: Exact dates of birth (DOB) for all enrolled students. - Physical Locations: Full residential addresses, cities/districts (such as Nampally, Telangana), and exact localized postal pincodes 2. Guardian and Parent Contact Registries - Parent Identity: Full names of both fathers and mothers linked directly to their children. - Direct Contact Methods: Active personal mobile numbers for parents, creating a severe vulnerability for automated spam or voice-phishing attacks. - Digital Contact: Parent email addresses intended for formal school updates. - Student Led Events - Teacher Certificates - gac-reports - Assessments 3. Proprietary LEAD School Academic Metrics - ELGA Placement Data: Internal academic tracking metrics, showing specific curriculum tiers like "ELGA Class" (e.g., ELGA02, ELGA06) and "ELGA Division" for individual students. - Classroom Analytics: Operational performance data exfiltrated directly from the nucleus.leadschool.in administrative portal. - Teacher Resources: Lesson plans, training modules, and classroom resources that form the core commercial assets of the LEAD platform. We told you this would be quick but now you learned your lesson. Hope everyone loves the leak. proof: https://mega.nz/folder/25hkSLgY#ELjJaFie-TfES9Z_47KFZA
Nintendo Company (Nintendo.com) · Jun 13, 2026proof: https://mega.nz/folder/3kBzQKgR#rIhDePsPMeFpfEGTPopDVQ We are ShadowByt3$ a extortion as a service group. We stole close enough to 1gb. You have 48 hours to contact us nintendo or all data gets leaked. If you contact us we give you an extra day to think this through. We are demanding a ransom payment of 2 million dollars. Check your inbox if you work for nintendo and use TINYpulse or go login to tinypulse if the url in the leak looks familiar. You have 48 hours from this announcement then it gets leaked. You have till June 15 2026. size: 859.0MB Close enough to 1GB it contains the following: -full name first name, last name, email of employees -analytics - surveys - all reports exported - all bank statements of payment pdf and w9 forms with employee ids - all cheers exported - all wins dashboard and wall of wins exported - all progress plans exported - Reports from 2016 to up to date 2026 - Analytics of Employees contain conversations and personal feelings about work and more - Content library of personal questions and engagement analytics - TINYpulse and Nintendo top employees of Nintendo based on engagement
Eric J Taylor Doxx · Apr 22, 2026
Stride Learning Full Breach (stridelearning.com) · Apr 21, 2026
Ellucian PowerCapus (ellucian.com) · Apr 21, 2026
Stride Learning (Stridelearning.com) · Apr 21, 2026
Ellucian PowerCampus Sample (ellucian.com) · Apr 17, 2026
Ellucian PowerCampus (ellucian.com) · Apr 17, 2026
Stride Learning Parent Company (stridelearning.com) · Apr 17, 2026
Amplify Technology (amplifytechnology.co.uk) · Apr 14, 2026
University Of Georgia (uga.edu) · Apr 14, 2026
UMSA Argentina · Apr 14, 2026
StarBucks (Starbucks.com) · Apr 14, 2026
Amplify_Technology_breached_032326 · Apr 12, 2026
Hotelogix (Hotelogix.com) · Apr 12, 2026
Proof Sample Hotelogix (Hotelogix.com) · Apr 12, 2026
https://anonfilesnew.com/7N0EOmzgCpg/sample_Pay_or_gets_leaked_and_sold_and_on_news. · Apr 10, 2026
sample_Pay_or_gets_leaked_and_sold_and_on_news · Apr 10, 2026
Sample_Forestal Atlántico Sur (FAS)_fas.com.uy · Apr 9, 2026
Pay_until_timer_runs_outForestal Atlántico Sur (FAS)_fas.com.uy · Apr 9, 2026
University_Of_Georgia · Apr 6, 2026
StarBucks_Sample · Apr 6, 2026
StarBucks_10GB_Pay_or_gets_leaked · Apr 6, 2026
nyayanagarpublicschool_in_part_1 · Apr 6, 2026
nyayanagarpublicschool_in_part_4 · Apr 6, 2026
nyayanagarpublicschool_in_part_2 · Apr 6, 2026
nyayanagarpublicschool_in_part_5 · Apr 6, 2026
nyayanagarpublicschool_in_part_3 · Apr 6, 2026
Eurobetscasino · Apr 6, 2026
UMSA_Argentina_All_15GB · Apr 6, 2026
$HADOWBYT3$_1.0_Leak · Apr 6, 2026
PGP_Verified_Public_key · Apr 6, 2026
UMSA_LEAK.7z · Feb 24, 2026

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .