ZeroHour

Search: “ShinyHunters”

150 items

ShinyHunters hackers claim breach of Florida "DAVID" DMV database

ShinyHunters claims it breached Florida's DAVID DMV database via a password-reset flaw, stealing 200,000+ driver records including SSNs.

The ShinyHunters extortion gang added Florida FLHSMV to its leak site, claiming theft of over 200,000 driver records from the DAVID platform since September 3. As proof, the group published a screenshot of Jeffrey Epstein's DMV record showing address, Social Security number, driver's license ID, and registered vehicles. The gang says it compromised DMV employee and FBI agent accounts via a password-reset flaw and iterated through records by ID. Access has reportedly been lost and the flaw is being patched, but ShinyHunters expects to announce breaches of other states' DMV platforms.

BleepingComputer · 8d agoData breach

McKesson copes with fallout from data theft extortion attack

McKesson discloses a data theft extortion attack by ShinyHunters affecting oncology and medical-surgical customers, with a reported $55 million demand.

McKesson disclosed that attackers gained access to some of its third-party applications and stole data associated with a subset of customers in its oncology, multispecialty, and medical-surgical business units; the intrusion ran for four days from August 21 and was discovered August 25. ShinyHunters claimed responsibility and listed McKesson on its data-leak site, reportedly demanding more than $55 million with a September 1 deadline. Flashpoint analysts say the group typically uses social engineering and identity weaknesses with valid credentials to access cloud-hosted environments, making the intrusion hard to detect. McKesson, which distributes about one-third of pharmaceuticals used in North America with $403.4 billion in annual revenue, says operations continue and it has reasonable assurance of no ongoing unauthorized activity.

CyberScoop · 16d agoData breach in the wild

ShinyHunters claims Florida DMV breach, puts data on the clock

ShinyHunters claims it breached Florida DMV's DAVID database, stole 200,000+ driver records including SSNs, and set a September 11 extortion deadline.

The ShinyHunters extortion group claims it breached the Florida Department of Highway Safety and Motor Vehicles' DAVID driver and vehicle database and stole more than 200,000 records. As evidence it published a screenshot of a Jeffrey Epstein record showing address, Social Security number, date of birth, license number and registered vehicles, and set a September 11 deadline before publication. The group says it obtained access through a password-reset weakness, compromised employee accounts, and queried and downloaded driver records and images. The Florida DMV has not confirmed the claim; it follows a separate confirmed IDScan.net breach exposing over 153 million license scans that prompted an FBI investigation.

CSO Online · 7d agoData breach in the wild1

ShinyHunters expose 6.4M in attack on medical supplier McKesson

ShinyHunters leaked stolen McKesson data exposing roughly 6.4 million individuals after the medical supplier reportedly declined a $55.2 million extortion demand.

Have I Been Pwned added records leaked by ShinyHunters from medical and pharmaceutical supply company McKesson, confirming the August 2026 attack affected about 6.4 million people. Exposed data includes names, email and physical addresses, dates of birth, phone numbers, employer details, and sensitive health information; ShinyHunters claimed SSNs and 284 million documents were taken, though HIBP found no SSNs. The group issued a $55.2 million extortion demand that was apparently unpaid before publication. The article also notes Boston Scientific expects to miss Q3 guidance after its own attack, and that Veradigm disclosed attackers used third-party vendor credentials to access an API and steal roughly 3.5 million patient records claimed by ransomware group The Gentlemen.

The Register · Securityupdated · 6d agofirst · 6d agoData breach 2 sources

ShinyHunters claims it stole 284 million patient records from McKesson

ShinyHunters claims theft of 284 million patient records from McKesson via vishing, Okta takeover, and Salesforce/Snowflake access, demanding $55,236,150.

McKesson disclosed in an SEC filing a cybersecurity incident detected August 25, 2026, involving unauthorized access to third-party applications and data exfiltration affecting a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. ShinyHunters told BleepingComputer it entered through vishing calls to employees, used stolen credentials to take over Okta single sign-on accounts, and extracted about a terabyte of data from Salesforce and Snowflake environments over four days. The group claims 284 million database rows including names, addresses, Social Security numbers, Medicaid details, medical record numbers, and medication data, and demanded $55,236,150 with a 72-hour deadline; none of these claims have been independently verified.

Help Net Security · 17d agoData breach

Florida confirms DMV database breached via stolen police account

Florida confirms its DAVID driver database was breached using stolen police credentials; ShinyHunters claims theft of 200,000+ records.

The Florida Department of Highway Safety and Motor Vehicles confirmed a breach of its DAVID driver database, learned of on September 4, 2026, and says the breach was quickly mitigated with none ongoing. Investigators found the attacker used compromised credentials of a single Plant City Police Department employee that were improperly stored on a personal electronic device. The ShinyHunters extortion gang claims it stole more than 200,000 driver records starting September 3 and shared a Jeffrey Epstein record as proof; FLHSMV has not confirmed the count. The agency notified the Florida Attorney General's office and is working with the Florida Digital Service and Florida Department of Law Enforcement.

BleepingComputerupdated · 16h agofirst · 5d agoData breach in the wild 3 sources1

ShinyHunters expose 6.4M in attack on medical supplier McKesson

Have I Been Pwned data shows ShinyHunters' attack on medical supplier McKesson exposed records of roughly 6.4 million individuals.

Have I Been Pwned added data from the McKesson breach, revealing that last month's cyberattack at the medical and pharmaceutical supply company affected roughly 6.4 million individuals. The extortion group ShinyHunters initially claimed to have stolen 284 million documents from McKesson. HIBP's addition of the ShinyHunters-leaked data is the first public indication of the attack's true scale.

DataBreaches.net · 6d agoData breach in the wild 2 sources

McKesson confirms cyber incident after ShinyHunters claims patient-data theft

Healthcare giant McKesson confirmed a cyber incident after ShinyHunters claimed theft of hundreds of millions of patient records.

McKesson acknowledged a data breach following public claims by the threat actor group ShinyHunters that it stole hundreds of millions of records containing patient data. The company confirmed a cyber incident occurred but the full scope of the theft has not yet been independently verified. ShinyHunters is known for large-scale data theft and extortion against major organizations. The healthcare sector remains a frequent target for data-theft extortion groups.

Malwarebytes Labs · 16d agoData breach

Hackers abused Claude to extract secrets from 1.8M Android apps

Anthropic reports ShinyHunters, Midnight Blizzard, and GTG-10007 misused Claude to automate credential theft, malware operations, and espionage against dozens of victims.

Anthropic's threat report details how ShinyHunters member 'frkoo' ran a credential-harvesting pipeline on ten AWS EC2 workers that mass-downloaded and decompiled 1.8 million Android APKs, scanning for hardcoded secrets with TruffleHog. In one AI-assisted operation, an actor extracted 2,100+ Azure AD authentication tokens across more than 40 Microsoft tenants in roughly 34 hours, and ShinyHunters affiliates also stole AI API keys and breached a SaaS provider affecting about 200 downstream customers. Russian espionage group Midnight Blizzard used Claude Code skills to automate malware development, phishing, C2, and exfiltration against 20+ government and defense entities, rebuilding malware automatically when detected. Chinese-linked GTG-10007 ran autonomous vulnerability research that uncovered zero-days in a major endpoint security product and hit roughly 50 organizations with confirmed compromises; Anthropic disrupted the abuse and banned the accounts.

BleepingComputerupdated · 5d agofirst · 5d agoThreat actor in the wild 16 sources1

Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device

ShinyHunters breached Florida's DMV using credentials stolen from a police officer's personal device; the state confirmed the breach and is investigating.

Florida's Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a data breach after ShinyHunters obtained DMV data using credentials a criminal actor took from a Plant City police officer's personal electronic device. The department learned of the breach on September 4, is investigating with the Florida Digital Service, and ShinyHunters shared a DMV record of Jeffrey Epstein as proof of access. Experts initially speculated a link to the IDScan breach of 153 million driver's licenses. Anthropic reported that suspected ShinyHunters affiliates use AI to scan credentials, map systems, and exfiltrate data, in one case moving from a stolen developer token to cloud admin access in about three hours.

The Recordupdated · 16h agofirst · 5d agoData breach in the wild 3 sources

AI lets small actors run state-level hacking campaigns, Anthropic report finds

Anthropic's threat report finds AI let a Russian-aligned espionage campaign, a Chinese student-run exploit foundry and ShinyHunters operators run state-grade operations.

Anthropic's report covering December 2025 to August 2026 details a Russian-aligned espionage campaign by actor 'JackPoterz' — matching Midnight Blizzard behaviors — against more than 20 government and defense organizations across Ukraine and Europe, with AI agents autonomously rebuilding Windows implants to evade detections. Chinese undergraduates ran an automated vulnerability-research foundry using Claude agent swarms, yielding more than a dozen potential zero-days in one month. ShinyHunters-affiliated operators used AI to dump over 2,100 Azure access tokens across 40 corporate tenants in 34 hours. Seven Chinese labs including Alibaba, DeepSeek, Moonshot AI, Xiaomi and Zhipu distilled Claude outputs; Alibaba peaked at nearly 3 million exchanges per day from more than 3,500 fraudulent accounts to train its Qwen systems.

CyberScoopupdated · 5d agofirst · 6d agoThreat actor in the wild 16 sources2· 1 read

AdaptHealth confirms 4.1 million people exposed in July cyberattack

AdaptHealth confirmed a ShinyHunters-attributed cyberattack exposed data of 4.1 million patients via a compromised third-party contractor account.

Healthcare company AdaptHealth confirmed 4,115,802 individuals were exposed in an intrusion first disclosed in an SEC filing on July 2, 2026, with the compromise beginning June 5. Attackers used social engineering to compromise a privileged third-party contractor account, accessed cloud-based patient management, document storage and EHR portals, and exfiltrated names, contact details, demographic, insurance and health information before a June 15 ransom demand. The attack was attributed to the ShinyHunters group, though the company no longer appears on the gang's extortion portal. Impacted individuals are being offered 12 months of free credit monitoring and identity protection.

BleepingComputer · 7d agoData breach1

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

Google and Mandiant attribute vishing-based SaaS data extortion attacks to UNC6671, now operating under the Redact, Pink, Helix, and Falcon brands.

Google Threat Intelligence Group and Mandiant track extortion group UNC6671, which uses vishing calls impersonating IT help desks to lure employees to adversary-in-the-middle phishing pages that capture credentials, MFA tokens, and session tokens. The group then registers adversary-controlled MFA devices, pivots through identity providers into Microsoft 365, Okta, and other SaaS applications, and runs automated Python and PowerShell exfiltration scripts. UNC6671 has rotated through extortion brands including BlackFile, Redact, Pink, Helix, and Falcon, and Google tracked over $10.6 million in Bitcoin payments between January 7 and May 12, 2026, with initial demands exceeding $3 million. The actor has hit dozens of organizations in North America, Australia, and the UK, shifting toward high-value financial and legal firms in July 2026.

The Hacker Newsupdated · 9d agofirst · 9d agoThreat actor in the wild 2 sources1

Hackers Leverage Claude to Exfiltrate Secrets from 1.8M Android apps

ShinyHunters-linked operators used Claude to scan 1.8M Android apps for hardcoded secrets, fueling intrusions across 40+ tenants.

Anthropic's September 2026 threat intelligence report describes a French-speaking operator (aliases MeowSHA, frkoo, blazespider) tied to ShinyHunters who ran 10 AWS EC2 workers and used Claude to decompile and scan 1.8 million Android APKs for hardcoded secrets with TruffleHog. Verified credentials were sorted into 100+ Telegram channels and paired with GitHub PAT harvesting, providing initial access for confirmed intrusions. In one supply-chain incident the actors extracted data from roughly 200 downstream customer organizations and dumped 2,100+ Azure AD token sets across 40+ corporate tenants in about 34 hours using AI agents. Anthropic banned tied accounts and stressed its own systems were not compromised.

Cyber Security News · 2d agoThreat actor1

Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories

Weekly roundup: Microsoft patches 973 flaws including two actively exploited zero-days; FortiOS CAPWAP flaw deploys PivotC2 RAT; PAN-OS root RCE disclosed.

Microsoft's September 2026 Patch Tuesday fixed 973 vulnerabilities, including two zero-days under active exploitation: CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack), both elevation-of-privilege bugs. SOCRadar reported active exploitation of CVE-2025-25249 (CVSS 9.8) in FortiOS CAPWAP, deploying a Node.js RAT called PivotC2 that exfiltrates Exchange mailboxes to Wasabi cloud storage; 178 devices were compromised out of 30,000 scanned IPs, attributed to a Russian-speaking financially motivated group. Palo Alto disclosed CVE-2026-0310, a 9.2-rated buffer overflow enabling root code execution on PA-Series firewalls, and Fortinet disclosed CVE-2026-84393, a ZTNA certificate validation MITM flaw. Cyera also revealed CVE-2026-6471 ('PostGREShell'), a 12-year-old PostgreSQL logical-decoding flaw allowing code execution via REPLICATION-privileged accounts.

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Microsoft links ShinyHunters- and Helix-affiliated actors to passkey-themed vishing and device-code phishing that compromises Microsoft 365 accounts and steals cloud data.

Microsoft attributes passkey- and SSO-themed social engineering activity, observed since May 2026, to Storm-3121 (linked to ShinyHunters and Falcon) and Storm-3032 (tied to BlackFile members now operating as Helix). Attackers impersonate corporate IT help desks by phone or SMS, urging fake passkey, MFA, or SSO updates and directing victims to adversary-in-the-middle phishing pages or device-code authentication flows that yield credentials, session tokens, and OAuth tokens. Post-compromise behavior includes Microsoft Graph enumeration of users, SharePoint, and OAuth grants, plus persistence via attacker-controlled MFA methods. Google Threat Intelligence tracks related activity as UNC6671, linked to the BlackFile, Helix, Falcon, Pink, and Redact extortion gangs.

BleepingComputerupdated · 19h agofirst · 5d agoPhishing & fraud in the wild 8 sources3

Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

Anthropic's 154-page report details Generative Threat Groups, including APT29-linked GTG-20006 and ShinyHunters affiliates, using Claude for reconnaissance, exploitation, and data theft.

Anthropic reports that between December 2025 and August 2026 state-sponsored hackers, criminals, spyware vendors, and propaganda operators used its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance. Notable clusters include GTG-50014, a ShinyHunters affiliate that scanned 1.8 million Android APKs for secrets via 10 AWS EC2 workers, GTG-10007, a Chinese-speaking group targeting roughly 50 organizations, and GTG-50029, a lone French-speaking actor exploiting a previously undocumented WordPress re-installation race condition. The report describes multi-agent frameworks autonomously executing reconnaissance, exploitation, and exfiltration against multiple victims, and influence operations that were disrupted before building authentic audiences.

The Hacker Newsupdated · 5d agofirst · 5d agoThreat actor in the wild 16 sources1

Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research

Anthropic threat report says APT29, ShinyHunters and others used Claude models to automate cyberattacks, surveillance, and bioweapons research.

Anthropic's latest threat intelligence report covers misuse of Claude Haiku, Sonnet, and Opus models across seven harm areas between December 2025 and August 2026. Russia's SVR espionage unit GTG-20006 (APT29/Midnight Blizzard/Cozy Bear) used AI to automate its full attack kill chain against more than 20 organizations across Ukraine, Europe, the Middle East, Asia, and North Africa. A ShinyHunters-linked supply-chain affiliate breached a SaaS provider and dumped over 2,100 Azure AD token sets spanning 40+ corporate tenants in about 34 hours, with AI agents performing nearly all the work. The report also documents five biological misuse cases (chikungunya, H5 avian influenza) and six conventional weapons development cases in China, Russia, and Yemen.

The Register · Securityupdated · 5d agofirst · 6d agoAI safety & security in the wild 16 sources

Mathspace discloses data breach affecting over 1 million people

Mathspace disclosed a Metabase breach exposing data of 1,079,819 students, parents, and staff in Australia and New Zealand.

Mathspace confirmed attackers exploited a vulnerability in its self-hosted Metabase reporting system, gaining administrator access without legitimate login and downloading data on over 1 million people (1,079,819 total) in Australia and New Zealand. Access began August 10, data was downloaded August 27, and the theft was confirmed September 3, 2026. No credentials, academic records, or school-account links were exposed, but affected individuals are warned of targeted phishing. The incident joins a broader campaign against Metabase instances, including Trezor's provider ShipMonk, Framework, and Tally, linked to ShinyHunters via extortion emails and leak-site listings.

BleepingComputer · 9d agoData breach in the wild

Trezor data breach impact now reaches 81,000 customers

Trezor's ShipMonk breach now affects 81,000 customers, adding 67,000 US customers after Metabase exploitation by ShinyHunters-linked attackers.

Trezor expanded its August 13 breach disclosure, saying the incident at shipping partner ShipMonk now affects 81,000 customers, with 67,000 additional US customers who ordered between November 2019 and August 2021 exposed. Attackers exploited a Metabase SQL injection zero-day to access ShipMonk's systems, exposing names, emails, phone numbers, shipping addresses, and order numbers; ShipMonk reportedly received extortion emails from the ShinyHunters gang. Trezor's own systems and devices were not compromised, and affected users are warned of phishing and scams. The broader Metabase campaign also hit Tally and Framework.

BleepingComputer · 9d agoData breach in the wild

Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack

Pharmaceutical giant McKesson disclosed a cyberattack on a third-party application that exfiltrated customer data, claimed by ShinyHunters.

McKesson reported a cybersecurity incident involving an unnamed third-party application, with attackers exfiltrating data tied to its oncology and surgical business units. The company filed with the SEC, offered credit monitoring, and said it had received reasonable assurance the attackers were no longer inside its systems. The ShinyHunters group claimed responsibility and threatened leaks; McKesson reported $106 billion in revenue last quarter and distributes about one-third of North American prescriptions.

The Record · 16d agoRansomware in the wild

Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database

ShinyHunters published hundreds of thousands of records from Florida's DAVID vehicle database, including SSNs and passports, after an unpaid ransom demand.

The ShinyHunters group published hundreds of thousands of files from Florida's DAVID motor vehicle database on its leak site, saying the victim did not pay a ransom. Stolen records include vehicle ownership certificates with names, addresses, and VINs, plus a smaller number of Social Security numbers, non-US passports, and immigration documents. FLHSMV confirmed the breach, which followed theft of a police officer's credentials stored on a personal device. It comes the same month as the IDScan hack exposing over 150 million driver's license images.

TechCrunch · Security · 16h agoData breach 3 sources