shinyhunters
ransomware group · aka ShinyHunters, UNC5537 (Mandiant/Google Threat Intelligence cluster linked in vendor reporting to the 2024 Snowflake-related campaign), UNC6040 / UNC6052 (Mandiant/Google clusters tied to the 2025 Salesforce social-engineering campaign), linked in public reporting to Scattered Spider (UNC3952) and the broader 'The Com' ecosystem, though the relationship is not formally confirmed · unknown; the name references Pokemon 'shiny hunting'. Press reporting has described individual members (e.g., a French national arrested in 2022 and later prosecuted in the US), but the group's leadership and base of operations are not publicly established. · active since 2020 (first publicly documented database sales and breach claims, per vendor and press reporting)
ShinyHunters is a financially motivated data-theft and extortion group first documented in 2020, known for selling or leaking large stolen databases on underground forums rather than deploying ransomware. Its widely reported track record includes Tokopedia and Wattpad (2020), DoorDash (2023), the Snowflake-related Ticketmaster and AT&T incidents (2024), and a 2025 wave of voice-phishing-driven Salesforce data thefts tied by Mandiant/Google to clusters UNC6040/UNC6052, affecting victims such as Santander, LVMH, Workday, Verizon, Qantas, and Google. The group monetizes through forum sales, data-broker listings, dedicated extortion/leak pages, and direct pressure on victims, and its operations overlap with Scattered Spider and 'The Com' ecosystem. Per this dashboard's leak-site tracking, ShinyHunters posted 3 victims in the last 7 days (a claimed State of Florida DMV breach, a Medela.com listing, and a note addressed to 'databroker1' regarding NEXUS DL Service), with the last post on 2026-09-07; these counts are dashboard-tracked, not lifetime totals. The group's precise membership and country of origin remain unknown.
- Large-scale data exfiltration followed by sale, leak, or extortion, typically without ransomware deployment (data-only extortion)
- Use of credentials harvested by infostealer malware to access cloud data platforms such as Snowflake (reported 2024)
- Voice phishing (vishing) and IT help-desk social engineering to obtain access to victims' Salesforce environments (reported 2025)
- Abuse of OAuth tokens and connected-app integrations (e.g., Salesloft Drift) to mass-access Salesforce tenant data (reported 2025)
- Sale of stolen databases on underground forums and via data-broker channels
- Countdown-style pressure tactics on victims ('data on the clock') via dedicated extortion pages
- Extortion outreach to executives and named individuals at victim organizations
- Collaboration or overlap with Scattered Spider / 'The Com' actors for intrusions and monetization
Tokopedia (2020), Wattpad (2020), Home Chef (2020), Minted (2020), Zoosk (2020), OkCupid (2020), Teespring (2020), Dave (2020), Mathway (2020), Arcadia Group / Topshop (2020)
No public figure.
Leak-site victims124 posts · newest first
| Victim | Discovered | Details |
|---|---|---|
| Kimberly-Clark | · 2d ago | This is a final warning to reach out by 16 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| State of Florida DMV | · 7d ago | Contact us, you know how. or we will release the files. View download button below for proof (samples). Deadline : 9 11 2026 |
| Medela.com | · 8d ago | This is a final warning to reach out by 08 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Note to mr. databroker1 NEXUS DL Service | · 11d ago | We've been trying to get ahold of you. We've made you several large offers for the data you possess (DL data). We don't believe you've seen them. I think you will appreciate the numbers we have to offer you in return for the data you possess. What we are willing to offer you can be considered a payment as large as what you would get paid in a ransom. Reply to the DMs we are sending you on forum or simply contact [email protected] |
| Neogen Corporation | · 16d ago | This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| McKesson Corporation | · 17d ago | Hundreds of millions of records/rows of data was compromised containing very sensitive information spanning from PII to PHI. We urge you to reach out. Read our emails. We will provide a substanial discount. Failure to engage with us will result in the full publication of data taken from you and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Elekta AB | · 17d ago | This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Jack Henry & Associates | · 17d ago | This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| CyrusOne, LLC. | · 22d ago | Update 23 Aug: We are removing the clients name off this post. They are refusing to pay a $13 million demand. They have 24 hours left to engage with us. We hold 12.9 million Salesforce records along with: Sharepoint: (369.6 GB Compressed / 645 GB Uncompressed) 288,729 Files, 60,513 Folders - More than 182,000 rows of Customer data Extracted from the "Contacts" Salesforce Object. - Over 8,300 Rows of Employee PII (Full Name, Email, Job Title, Phone Number, ect.) - Thousands of executed contracts, MSAs, NDAs, amendments, leases, and SOWs - Extensive physical key inventory logs, verification photos, and contractor Green Badge audits - Large collection of data center drawings, floor plans, electrical one-line diagrams, security system drawings, and site schematics - Full CERM (Critical Environment Reliability Management) process library - Physical and information security policy suite plus governance materials - Regional security scorecards, KPI workbooks, GAM sheets, and signed performance packages - Credential and access-control artifacts (including PasswordList.xlsx, Okta SSC Access lists, active badge reports, and multiple Data Center Access Control forms)This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| ReliaQuest, LLC | · 23d ago | This time the post is about you, not us. Let Mandiant report and advise on us accurately, go away. DISCLAIMER: This information is being provided "as is" for informational purposes only. We do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this post. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favour by us. |
| NovoCure Limited | · 24d ago | This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| BOK Financial | · 24d ago | This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Cyrus****** | · 26d ago | This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Logitech/ Streamlabs | · 28d ago | This is a final warning to reach out by 21 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Brinks Home | · 28d ago | Over 4.9 million Salesforce records containing some PII was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
| Alcon, Inc. | · 28d ago | Over 25 million Salesforce records containing some PII was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
| Lumenis Ltd. | · 28d ago | Over 1.1 million records containing some PII of customers/employees and 177GB+ of internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
| Questel SAS | · 28d ago | Over 21 million Salesforce records containing some PII and 147GB+ of internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
| Metabase | · 28d ago | :P |
| Sharecare, Inc. | · 28d ago | This Company data was published due to them hiring a very incompetent and unskilled negotiator. If you choose incompetency to negotiate for you, that is on you. We will be publishing companies data who are negotiating with us, without a warning if negotiators continue to take us as misinformed individuals and BS us. Over 3.4 million Salesforce records containing some PII and 28GB+ of internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
| NOTICE OF WARNING | · 28d ago | We are currently experiencing an influx of volume. More leaks are on their way. Kindly be informed, it is in your best interests to not stall and waste our time. Just pay and get it over with. We are on short temper and patience. We are the ones with the leverage, not you. Don't be naive. If you aren't with the program, go away. Your data will be published immediately and accordingly. SH |
| Carhartt, Inc. | · 28d ago | Our demand for this Company was $3.3 million. The Company reached out. However, The Company did not try to negotiate. If The Company attempted to negotiate with us The Company would've ended up saving a good chunk of money. Instead they decided to do (see blow); this is also because The Company hired a very unskilled and incompetent negotiator. If The Company hired competency to negotiate for them, this post would've never been published. [21:24:22] carhartt: After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions. We appreciate your patience throughout this process. There is millions of customers of data involved here. As we always say, these companies don't care. Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
| Cook Medical LLC | · 28d ago | Customer data, employee data, and other internal corporate data was compromised. The Company engaged with us but made several paltry offers, did not want to pay what we asked for and decided they are okay with the data leak to happen instead of increasing their offer by a little, then we'd likely have accepted and this post would not have gone up. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
| Baxter International, Inc. | · 28d ago | Over 7.1M Salesforce records containing some PII was compromised. This is a final warning to reach out by 17 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| BH Security, LLC. (brinkshome.com) | · Jul 27, 2026 | Over 4.9 million Salesforce records containing some PII was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| RingCentral, Inc. | · Jul 27, 2026 | Over XX of data was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Ernst & Young | · Jul 27, 2026 | Yes it was us. Now come talk to us. We have been trying to reach you. If you do not come talk to us within the given deadline, we fully and completely intend to release all the data and files. This is a final warning to reach out by 31 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| [cdn] Notification | · Jul 25, 2026 | All CDN mirrors are currently experiencing a service disruption. All files are fully backed up and no data has been lost. At this time we do not have an estimated time of resolution.We are working to restore service promptly and will share updates as they become available. |
| Abbott owned Exact Sciences Corporation | · Jul 15, 2026 | You wouldn't want us to describe what was exfiltrated from you publicly. This is a final warning to reach out by 18 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Fluke Corporation | · Jul 6, 2026 | Over 21 million Salesforce records containing some PII were compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
| Ingram Content Group, Inc. | · Jul 6, 2026 | The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
| icsecurity.com | · Jun 19, 2026 | Over 2.7 million records and other internal corporate data was compromised. This is a final warning to reach out by 22 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Amazon owned OneMedical.com | · Jun 18, 2026 | Over 8.8TB of data was compromised. This is a final warning to reach out by 22 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| NAIC.org | · Jun 18, 2026 | Over 3.1 terabytes of National Association of Insurance Commissioners data (105,000+ files) was compromised across the INSData statistical platform, Vision credit rating feeds, SERFF, OPTINS, UCAA, EDP, RDC, and state insurance department reporting systems (NAIC, all fifty state insurance departments, and thousands of licensed insurers), including 2.1 million insurer regulatory filing PDFs, 40,000 quarterly statistical CSVs with federal EINs and company data, 45,000+ licensed rating agency files from Moody's, Fitch, S&P, Kroll, DBRS, and AM Best with CUSIP and ISIN identifiers, statutory annual and quarterly financial statements, premium and loss statistics, and HR Ratings master data. This is a final warning to reach out by 22 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Service Notice: Scheduled Maintenance and Infrastructure Upgrades | · Jun 17, 2026 | * The primary server hosting all leaked data is currently undergoing scheduled maintenance and will be unavailable for approximately 24 hours. * To improve your downloading experience, we are currently deploying multiple data mirrors which you can see by clicking the "Download" button to ensure faster, more reliable download speeds. Additionally, we will soon offer torrent links for all hosted files to provide a more robust distribution network. * No data has been lost as we keep several backups of everything that has been leaked on here since Day 1. These files will remain publicly accessible with ease till the end of time. We appreciate your patience as we upgrade our infrastructure. |
| Ralph Lauren | · Jun 16, 2026 | Over 220GB of data containing customer PII, purchase/trasnaction info, future unreleased releases from 2027 and onward, and more was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. |
| icc.edu | · Jun 15, 2026 | Over 28 gigabytes of Illinois Central College data (122,000+ files) was compromised across PeopleSoft Campus Solutions and Human Resources (ICC, SURS pension reporting, Workday costing, and ICCB curriculum systems), including 9,200+ employee payslip PDFs, 500+ SURS payroll files with Social Security numbers, direct deposit records with bank account and routing numbers, student financial aid and grade roster exports, enrollment CSVs with @icc.edu accounts, and Workday salary allocation data spanning 2021 through June 2026. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| moody.edu | · Jun 15, 2026 | Over 23 gigabytes of Moody Bible Institute data (1,300+ files, tens of millions of records) was compromised across enrollment, donor relations, payroll, and communications systems (MBI, EDC/Salesforce leads, PeopleSoft PS_COMMUNICATION, Horizon SIS, WHPD donor database, and Cadence admissions), including 46 million communication records, 2.2 million enrollment lead records, 108,000 biodemographic master files with addresses and birthdates, 3.3 gigabytes of donor gift data, employee payroll XML with home addresses and earnings, 1,100+ admissions outreach files, and student housing assignment records. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| glendale.edu | · Jun 15, 2026 | Over 62 gigabytes of Glendale Community College data (304,000+ files) was compromised across PeopleSoft Campus Solutions (GCC, integrations, financial aid, and admission processing), including 150,000+ student records with names, dates of birth, and @student.glendale.edu emails, login and enrollment mapping files, new student enrollment CSVs, immunization compliance logs, admission checklist reports, financial aid batch exports, and transcript PDFs spanning September 2020 through June 2026. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| hccs.edu | · Jun 15, 2026 | Hundreds of thousands of student records containing full name, home address, phone, email, date of birth, gender, ethnicity, enrollment status, GPA, major, and student ID across all campuses. Daily and full student roster exports library credentials, PINs, and @student[.hccs[.edu accounts. Over 12,000 financial aid and bursar reports including FAFSA/ISIR suspense data with names, birthdates, emails, phones, and home addresses. Class rosters with birthdates, grades, academic programs, and contact information for tens of thousands of enrolled students per term. Over 344,000 international student documents including SEVIS I-20 forms, visa applications, passports, bank statements, tax returns, immigration affidavits, and acceptance letters. Over 14,000 student immunization and vaccination records including meningitis compliance documentation. Over 15,000 additional health and immunization documents across report archives and A LOT more was compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| kodak.com | · Jun 15, 2026 | Over 2.2 million records containing customer PII and other internal corporate data was compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Deep Well Services | · Jun 15, 2026 | Over 7k records containing customer PII and other internal corporate data was compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Sysco Corporation | · Jun 15, 2026 | Over 61 million Salesforce records across several tables, some containing customer data/PII, employee data, and other internal corporate data was compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| coe.int | · Jun 14, 2026 | Over 297 GB of Council of Europe HR and payroll data (429,000+ files) was compromised across the Secretariat, Directorate of Human Resources, Parliamentary Assembly, EDQM, permanent and temporary staff, interpreters, conference services, language booth units, and payroll administration, including 409,000+ payslips for 10,000+ staff from 2011 to 2026, 14,000+ CVs and 3,700+ in-house personnel files, 10,700+ per-employee document stores, contract and purchase order records, mission travel overpayments, interpreter scheduling and 2026 salary scales, Blue List rosters, absence and illness reports, bank account and URSSAF payroll data, performance evaluations, and payroll exports, covering full names, employee IDs, home addresses, phone numbers, dates of birth, salaries, bank details, tax and social security information, medical and absence records, mission references, and other internal institutional data. This is a final warning to reach out by 16 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Madison Square Garden Sports Corp. | · Jun 12, 2026 | Over 26 million records containing customer PII and other internal corporate data was compromised. This is a final warning to reach out by 15 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| JCPenney & several other subsdiaries under Catalyst Brands & Authentic Brands Group | · Jun 12, 2026 | Hundreds of thousands of records containing PII (SSN, DOB, etc.), W-2 tax records, pay data, physical scans of government identity documents, drive licenses, and a lot more was compromised. This is a final warning to reach out by 15 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| American Tower Corporation | · Jun 12, 2026 | Over 5.2 million records consiting of a significant amount of customer and landowner PII, other records tied to other companies such as T-Mobile, Verizon, and the US DHS, several tower asset records containing GPS data and plaintext physical access/gate codes for cell tower compunds across the United States, thousands of internal corporate data, and a lot more were compromised. We urge you to reach out. This is a final warning to reach out by 15 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Zayo.com & Allstream.com | · Jun 12, 2026 | You wouldn't want us to describe what data was taken from you publicly here. A fair assessment of this breach in terms of criticality is a 9/10. We urge you to reach out. Read our emails. Failure to do so will result in the full publication and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 16 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Nexstar.tv | · Jun 12, 2026 | Over 1 million Salesforce records and other internal corporate data containing PII was compromised. This is a final warning to reach out by 14 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |
| Ralph Lauren Corporation | · Jun 12, 2026 | Over 220GB of data containing customer PII, purchase/trasnaction info, future unreleased releases from 2027 and onward, and more was compromised. This is a final warning to reach out by 14 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. |