ZeroHour

shinyhunters

ransomware group · aka ShinyHunters, UNC5537 (Mandiant/Google Threat Intelligence cluster linked in vendor reporting to the 2024 Snowflake-related campaign), UNC6040 / UNC6052 (Mandiant/Google clusters tied to the 2025 Salesforce social-engineering campaign), linked in public reporting to Scattered Spider (UNC3952) and the broader 'The Com' ecosystem, though the relationship is not formally confirmed · unknown; the name references Pokemon 'shiny hunting'. Press reporting has described individual members (e.g., a French national arrested in 2022 and later prosecuted in the US), but the group's leadership and base of operations are not publicly established. · active since 2020 (first publicly documented database sales and breach claims, per vendor and press reporting)

Victims · 7d
1▼2
Victims · 30d
24active targets
Victims · 90d
32
All-time (tracked)
124since 2026-01-23
Last post
09-13 15:47UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

ShinyHunters is a financially motivated data-theft and extortion group first documented in 2020, known for selling or leaking large stolen databases on underground forums rather than deploying ransomware. Its widely reported track record includes Tokopedia and Wattpad (2020), DoorDash (2023), the Snowflake-related Ticketmaster and AT&T incidents (2024), and a 2025 wave of voice-phishing-driven Salesforce data thefts tied by Mandiant/Google to clusters UNC6040/UNC6052, affecting victims such as Santander, LVMH, Workday, Verizon, Qantas, and Google. The group monetizes through forum sales, data-broker listings, dedicated extortion/leak pages, and direct pressure on victims, and its operations overlap with Scattered Spider and 'The Com' ecosystem. Per this dashboard's leak-site tracking, ShinyHunters posted 3 victims in the last 7 days (a claimed State of Florida DMV breach, a Medela.com listing, and a note addressed to 'databroker1' regarding NEXUS DL Service), with the last post on 2026-09-07; these counts are dashboard-tracked, not lifetime totals. The group's precise membership and country of origin remain unknown.

Tactics & tooling
  • Large-scale data exfiltration followed by sale, leak, or extortion, typically without ransomware deployment (data-only extortion)
  • Use of credentials harvested by infostealer malware to access cloud data platforms such as Snowflake (reported 2024)
  • Voice phishing (vishing) and IT help-desk social engineering to obtain access to victims' Salesforce environments (reported 2025)
  • Abuse of OAuth tokens and connected-app integrations (e.g., Salesloft Drift) to mass-access Salesforce tenant data (reported 2025)
  • Sale of stolen databases on underground forums and via data-broker channels
  • Countdown-style pressure tactics on victims ('data on the clock') via dedicated extortion pages
  • Extortion outreach to executives and named individuals at victim organizations
  • Collaboration or overlap with Scattered Spider / 'The Com' actors for intrusions and monetization
Targeted sectors
technologye-commerce/retailhospitality/entertainmenttelecomfinancial servicestravel/airlinesluxury goodshealthcare
Notable public victims

Tokopedia (2020), Wattpad (2020), Home Chef (2020), Minted (2020), Zoosk (2020), OkCupid (2020), Teespring (2020), Dave (2020), Mathway (2020), Arcadia Group / Topshop (2020)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Vertex Inc. · Mar 9, 2026Over 2M records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 12 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Salesforce Aura Campaign · Mar 9, 2026Several hundreds of companies set to release with FINAL WARNINGs upon failure to comply. To all affected companies who will be or are being contacted by us ("ShinyHunters"), please consider this a preliminary warning before we release your name with FINAL WARNING or a complete data leak. Reply, engage, pay a small price, and prevent a publication. Make the right decision, don't be the next headline.
CFGI Management, LLC. · Mar 6, 2026Over 800k records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 09 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Pathstone.com · Mar 6, 2026Salesforce records were compromised and other internal corporate data have been compromised. The company failed to reach an agreement with us despite all the chances and offers we made. They don't care about their clients nor investors.
Woflow, Inc. · Mar 3, 2026Several hundreds of millions of records containing PII, transaction/order data, other internal corporate data, and a lot more (you don't want us to say publicly) have been compromised. This is a final warning to reach out by 06 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Pathstone Family Office, LLC · Feb 27, 2026Over 641k records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 2 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Odido NL & Ben.nl · Feb 23, 2026Almost 21M records containing Full Names, Physical addresses, email addresses, phone numbers, and plaintext passwords, IBAN, passport numbers, driver license numbers and other internal corporate data have been compromised. This is a final warning to come back to our chat and finish what we set out to do before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. You know where to find us.
Beacon Pointe Advisors · Feb 21, 2026Over 100k Salesforce records were compromised including over 59k containing PII and other internal corporate data have been compromised. The company failed to reach an agreement with us despite all the chances and offers we made. They don't care about their clients nor investors.
Wynn Resorts, Limited. · Feb 20, 2026Over 800k records containing PII (SSNs, etc.) and employee data have been compromised. This is a final warning to reach out by 24 Feb 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
CarGurus, Inc. · Feb 18, 2026Over 1.7M records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 20 Feb 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Mercer Advisors · Feb 16, 2026Over 5 million records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 18 Feb 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Beacon Pointe Advisors, LLC. · Feb 16, 2026Over 100k+ records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 18 Feb 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.
Canada Goose · Feb 14, 2026Over 600k records containing PII and payment/financial information have been compromised.
Figure Technology Solutions, Inc. · Feb 13, 2026Thousands of applicants of Figure.com PII were compromised. They decided to waste time and hide instead because their leadership is a mess and can't make a decision.
University of Pennsylvania · Feb 4, 2026"Fewer than 10 records"* ;) containing PII and donation data have been compromised. *: More like 1.2 million
Harvard University · Feb 4, 2026Over 1 million records containing PII and donation data have been compromised. This is the direct result of advisors advising you against paying a ransom. It has the opposite effect. Do NOT provoke us again and pay the ransom when we contact you.
Bumble Inc. · Jan 28, 2026Thousands of internal documents from Bumble. Our exfiltration focused on documents designated at restricted or confidential. Files primarily from Google Drive and Slack.
Match Group · Jan 27, 2026Over 10 million records of Hinge, Match, and OkCupid usage data from Appsflyer and hundreds of internal documents.
Panera Bread · Jan 27, 2026Over 14 million records containing Personally Identifiable Information (PII) have been compromised.
Edmunds.com, Inc. · Jan 24, 2026
CarMax, Inc. · Jan 24, 2026
Betterment, LLC. · Jan 23, 2026
Crunchbase, Inc. · Jan 23, 2026
SoundCloud · Jan 23, 2026

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .