Gotta Breach 'Em All! The Journey Of ShinyHunters
IntroductionSekoia’s Threat Detection & Research (TDR) team has been actively tracking ShinyHunters 2026-10-1 07:33:26 Author: www.sekoia.com(查看原文) 阅读量:19 收藏

Introduction

Sekoia’s Threat Detection & Research (TDR) team has been actively tracking ShinyHunters for several months. Today, ShinyHunters is best understood not as a fixed gang but as a financially motivated data theft and extortion brand. A group that has persisted since 2020 across changing membership, surviving multiple arrests and forum seizures along the way. 

The name comes from the Pokémon community, where "shiny hunters" are dedicated gamers whose purpose is to find rare color variant ("shiny") Pokémon, like their early forum avatar which was a shiny Umbreon. In that context, could shiny hunting be working through targets methodically until something rare and valuable surfaces? Personally identifiable information (PII), credentials, and extensive user databases align with this framework.

Screenshot of a ShinyHunters forum profile showing an enlarged avatar depicting a blue, fox-like fantasy creature with glowing markings and stars.

ShinyHunters' forums avatar

In practice, the group, today, functions as a decentralized network of threat clusters operating under a common alias. We assess with high-confidence their link with "The Com", the broader cybercrime community that also includes Scattered Spider and Lapsus$, an association that became explicit in 2025 with the formation of Scattered Lapsus$ Hunters. Their modus operandi remains consistent throughout: obtain valid credentials or access, exfiltrate bulk data, then monetize the breach through extortion or illicit sales. What has changed over time is how they get access. The evolution of this threat actor is defined by a clear progression in their access methodologies:

  • Early phase: Traditional phishing and large-scale forum credentials dumps.
  • Transition phrase: Exploitation of infostealer data targeting cloud infrastructure lacking Multi-Factor Authentication (MFA).
  • Current phase: Advanced SaaS supply-chain compromises and OAuth token theft. 

Missing or weak MFA has been the recurring root cause across several of their largest breaches, though more recent campaigns increasingly exploit cloud misconfigurations and OAuth trust relationships rather than credentials alone.

This report is done in collaboration with Beazley Security. In addition to open-source intelligence and prior public reporting on ShinyHunters’s activity since its emergence. This report will benefit from first-hand incident response data contributed by Beazley Security’s team, who investigated a recent compromise. Beazley Security offers, among other services, incident response for cyber security breaches and often assists with ransomware cases. A ShinyHunters campaign in May 2026 presented an opportunity for the Beazley Security Labs team to analyze and document current TTPs of this threat actor.

This report does not aim to be exhaustive. A complete record of every claimed or confirmed ShinyHunters incident would be the size of a book. Instead, we chose to focus on the events and shifts we assess as most significant to understanding the group: changes in tactics, structure, and law enforcement posture, alongside the most notable leaks and breaches attributed to them. Throughout, we are transparent about where evidence is solid, where it's disputed, and where we simply don't know. Our aim is to make sense of a group whose activity spans years, aliases, and shifting membership, and to provide an up-to-date picture of where things stand as of this writing.

Origins

ShinyHunters' lineage traces back through two earlier hacking collectives, TheDarkOverlord and GnosticPlayers, in a chain researchers describe as sharing continuity of personnel rather than just similarity of style. TheDarkOverlord emerged first. It is a group focused on extortion, active from around 2016, and whose victims included Disney, Netflix, several medical facilities, and an entire city's school districts. GnosticPlayers subsequently emerged, between 2018 and 2019 for breaching dozens of companies and selling nearly a billion stolen records from services like MyFitnessPal and Dubsmash, largely through credential-stuffing attacks against developers' GitHub accounts.

The nexus between these entities and ShinyHunters is rooted in concrete personnel overlap, rather than just shared attack patterns. Researchers actually name individuals who were in both groups, which serves as a much stronger basis for attribution than behavioral similarities alone. Cybersecurity researcher Vinny Troia's 2020 investigative report identified GnosticPlayers' core members as Maxime Thalet-Fischer (aliases DDB, Casper, RawData, Pumpkin), the group's seller, and Nassim Benhaddou (alias "Prosox"), a member described as an early associate of Gabriel Kimiaie-Asadi Bildstein (alias “Kuroi’SH”), a French hacker who resurfaces later in this report as one of the three ShinyHunters defendants. Troia specifically credits Benhaddou with later forming ShinyHunters. All three were swept up in the same 2019 law enforcement action, arrested after Bildstein confessed to a breach of the crypto platform GateHub that involved the theft of roughly $9.5 million in cryptocurrency. Corroborating open-source intelligence from CPO Magazine's reveals a pre-existing offline connection between Benhaddou and Bildstein. The two associates (friends) share a prior arrest in Paris in 2018 over an unrelated YouTube defacement incident. Asserting it was Benhaddou who went on to start ShinyHunters after Bildstein temporarily dropped out of the scene.

It's worth noting this attribution is contested by the people involved. When DataBreaches[.]net separately reached both Benhaddou and Bildstein directly in 2022, following a fresh round of arrests, both acknowledged their earlier roles in GnosticPlayers but specifically denied ever being part of ShinyHunters. That denial doesn't erase the documented overlap. Bildstein was, after all, later named in the 2021 US federal indictment of ShinyHunters. But it's a reminder that the GnosticPlayers to ShinyHunters lineage rests substantially on researcher attribution rather than on confirmed admission, and should be presented with that caveat.

2020: The genesis

Timeline of ShinyHunters’ major events in 2020, categorized by tradecraft and campaigns, breaches and extortion, and law enforcement, including prominent data breaches and leaks from May through November.

ShinyHunters' 2020 activity timeline: key events and operations

ShinyHunters first appeared publicly on cybercrime forums around April or May 2020, though some sources place the group's formation as early as 2019, a date that isn't firmly established. From the outset, its operating model was consistent: 

  • steal data, 
  • sell it privately on darkweb markets and RaidForums, 
  • and once a dataset's profitability dried up, release it for free to build reputation. 

Early access relied heavily on credential and token abuse, particularly hunting for exposed GitHub OAuth tokens and misconfigured AWS S3 buckets.

May marked the group's public debut. Its earliest confirmed target was Mathway (~25M records), though this rests on secure.com's account rather than broad consensus and the dating itself is messy. The actor told ZDNet the Mathway intrusion actually happened in January 2020, even though the breach didn't surface publicly until late May, with Mathway confirming it around May 15. Within roughly two weeks of surfacing, ShinyHunters had already listed over 200 million records from about 11 companies for sale, priced between $500 and $2,500 each. The confirmed victims included Tokopedia (~91M), Unacademy (~22M), HomeChef (~8M), Chatbooks (~15M), Zoosk (~30M), Minted (~5M), Wishbone (~40M), and Chronicle[.]com (~3M). The group also claimed to have stolen roughly 500GB from Microsoft's private GitHub repositories, releasing about 1GB as a proof. Microsoft investigated but never confirmed a meaningful breach, noting the leaked samples resembled test projects rather than production code.

June brought the first legal consequences. The Wishbone breach triggered a class-action lawsuit, filed June 4, against maker Mammoth Media over the roughly 40 million affected users. The Havenly breach (~1.3M) also occurred in this window, though it wouldn't be publicly leaked until the following month. A pattern of delayed disclosure that recurs throughout the group's history, as later covered in threat research by Vinny Troia and Night Lion.

July was the most consequential month of the year, dominated by a massive free release. Fintech app Dave disclosed a breach of roughly 7.5 million records on July 25, traced to a supply-chain compromise of third-party analytics vendor Waydev. Wattpad suffered its largest breach of the year at roughly 270 million records, a dataset that had previously been priced privately near $100,000. Then, starting July 21, ShinyHunters dumped over 386 million records from 18 companies for free on RaidForums. Nine previously known victims and nine new ones, including Havenly, Indaba Music, Ivoy, ProctorU, Rewards1, Scentbird, Vakinha, Drizly, Appen, Mathway, and Promo[.]com. The group told BleepingComputer  they had released it simply because they had already made enough money from it.

August saw a breach whose full impact wouldn't be known for months. The Indian payment processor Juspay was compromised, exposing roughly 35 million records. The company was aware of the incident quickly but chose not to disclose it to users until January 2021, after independent researcher Rajshekhar Rajaharia made it public on his own.

September was comparatively quiet, with the main event being a breach of a Singapore hotel booking platform RedDoorz around September 4, affecting roughly 5.8 million records and later attributed to ShinyHunters.

October introduced a victim that would resurface repeatedly over the following year. The Australian PDF software firm Nitro PDF (GoNitro) had roughly 77 million records and document metadata stolen. The breach was disclosed in October, though the full free dump wouldn't appear until January 2021. In the meantime, the data was put up for private auction, with Cyble reporting a starting price around $80,000. Nitro itself downplayed the incident publicly on October 21, describing it as a "low impact security incident".

November closed out the year with a cluster of unrelated breaches. BigBasket, an Indian online grocery platform, had roughly 20 million customer records sold for about $40,000. Cyble flagged the sale on November 7, and BigBasket had already filed a police report the day before. Animal Jam, a children's virtual world game run by WildWorks, had roughly 46 million accounts leaked between November 11 and 16, following a compromised Slack token that gave attackers third-party access. Mashable had a 5.22GB database leaked around November 5. And Pluto TV, ViacomCBS's streaming service, had roughly 3.2 million user records exposed.

2021: From leaks to extortion, and first indictments 

Timeline of ShinyHunters’ major events in 2021, categorized by tradecraft and campaigns, breaches and extortion, and law enforcement, including data dumps, reposted records, alleged customer data leaks, and indictments.

ShinyHunters 2021 activity timeline: key events and operations

By 2021, ShinyHunters' activity as a data theft crew was already winding down, even as the law enforcement story around them was just beginning. When the United States Department of Justice (DOJ) eventually indicted the group's alleged members later that year, and when Sébastien Raoult pleaded guilty still later in 2023, the filings finally confirmed what security researchers had long suspected about the group's initial access method. Phishing emails leading victims to fake login pages, harvested credentials, and a pivot from there into corporate networks and third-party cloud storage providers. It's also worth noting that several of the dumps released in January 2021 weren't new intrusions at all. They were data stolen back in 2020 that recirculated for reputation once ShinyHunters judged them no longer worth selling privately.

January opened with another “mega” dump. In a single wave, the group leaked roughly ten new databases for free on RaidForums, exposing over 125 million credentials. Pixlr contributed with 1.9 million records, likely pulled from an unsecured AWS S3 bucket, while Bonobos suffered the loss of a full cloud backup database of around 7 million customer records. The same wave swept in Wognai, Tesspring, Tuned Global, Wappalyzer, Rooter, and MeetMindful. The latter was posted January 20 and confirmed by the company four days later, exposing 2.28 million records. The full Nitro PDF database of 77 million records, stolen the previous autumn, was also released free that month. India suffered the most. Crypto wallet BuyUCoin, wedding platform WedMeGood, classifieds ads website ClickIndia and fintech Chqbook all had data surface that month, alongside the longly delayed public confirmation of the August 2020 Juspay breach (~35M).

February and April brought less new activity than recycled notoriety. On February 5, a user going by "sl4ckto" reposted the RedDoorz breach (~5.8M from September 2020) for free on RaidForums, with the leak attributed back to ShinyHunters. April was quieter, marked by a single partial dump of Indian stock broker Upstox, a company that had already disclosed a security incident and forced its users through password resets before the leak surfaced.

Then, in June, the law caught up. On June 23, a grand jury in the Western District of Washington indicted three French nationals tied to the ShinyHunters conspiracy: Sébastien Raoult (known online as "Sezyo Kaizen"), Gabriel Kimiaie-Asadi Bildstein ("KuroiSH," also linked to the earlier Gnostic Players group)  and Abdel-Hakim El Ahmadi ("Zac" / "Jordan Keso"). The charges covered the group's activity from April 2020 through June 2021. Data stolen from more than 60 companies and sold across RaidForums, EmpireMarket, and Exploit, amounting to hundreds of millions of records and more than $6 million in victim losses. But the indictment didn't stop the group from surfacing again two months later. 

In August, ShinyHunters listed data of roughly 70 million alleged AT&T customers. Including phone numbers, dates of birth, social security numbers (SSNs), with an asking price starting around $200,000. AT&T denied any breach of its systems, a denial it would maintain even after the same dataset resurfaced for free in 2024. The source of the data remains disputed to this day. That same month, Intel 471 and The Hacker News published a detailed writeup of the group's tactics, confirming their pattern of hunting company GitHub repositories for exposed credentials and API keys as a pivot point into cloud infrastructure. By this point, the group's online avatar, the shiny Umbreon Pokémon, was a recognizable signature on RaidForums, where they primarily operated.

In December, the group's methods had shifted further toward outright extortion. The Indian retailer ABFRL was breached and held to ransom. When the ransom was reportedly refused, ShinyHunters dumped data tied to 5.4 million records.

2022: Disrupted operations

Timeline of major ShinyHunters-related events in 2022, including RaidForums outages, its seizure by law enforcement, the launch of BreachForums, and arrests of suspected administrators.

ShinyHunters 2022 activity timeline: key events and operations

If 2021 was the year the law started closing in, 2022 was the year the ground genuinely shifted under ShinyHunters. On one hand, the destruction of the forum infrastructure the group had relied on since its earliest days. On the other hand, the first physical arrest of one of its charged members. Compared to the relentless breach cadence of 2020 and 2021, the new intrusions branded ShinyHunters were scarce and comparatively low profile that year. The group began moving from "data thief" toward "forum operator” and acting as a “brand", a shift that sets up much of what follows from 2023 onward. It's also worth flagging that attribution gets murkier from this point. As ShinyHunters' name grew more notorious, it started being impersonated by other actors. Consequently, any intrusions attributed to their moniker in 2022, requires an extra scrutiny before being folded into the group's verified operational history.

The unraveling began slowly, in February. RaidForums, the marketplace that had hosted nearly all of ShinyHunters' 2020 and 2021 sales and leaks, went mysteriously offline around the 25th, following a string of outages between February 7 and 12. When the site briefly resurfaced, it displayed nothing but a login page, later assessed by researchers as a law enforcement honeypot designed to harvest credentials from returning users. It was a strong signal that authorities already had access to the forum's backend well before any public announcement.

The community had already begun regrouping elsewhere by March. A prominent RaidForums user known as "Pompompurin" (later identified as Conor Brian Fitzpatrick) launched BreachForums as an almost identical clone of its predecessor, preserving the same audience and the same “buy/sell/leak” business model. That same month, UK's National Crime Agency made its own move, arresting a 21 year-old in London, a suspected RaidForums administrator, as part of Operation TOURNIQUET.

The reason for RaidForums' silence became public in April. On the 12th, the DOJ and Europol jointly announced the forum's seizure, encompassing its main domains (raidforums[.]com, rf[.]ws, raid.lol). It was the culmination of a year-long international operation spanning the US, UK, Sweden, Portugal, Romania, and Germany, targeting a platform that had hosted more than 10 billion stolen records since 2015. The forum's founder and administrator, 21-year-old portuguese Diogo Santos Coelho (known online as "Omnipotent"), had in fact been arrested weeks earlier, on January 31 in Croydon, and was charged in the Eastern District of Virginia with conspiracy, access device fraud, and aggravated identity theft. For ShinyHunters, the strategic damage was significant. Their primary distribution and monetization channel was gone, accelerating their migration to BreachForums, which was already underway.

Then, in May, law enforcement caught up with one of the group's members. On May 31, Sébastien Raoult, the French national operating under the usernale  "Sezyo Kaizen" and one of three suspects named in the US indictment in June 2021, was arrested at a Moroccan airport while attempting to leave the country, acting on a US Interpol Red Notice. He was held in Morocco pending extradition. His two co-defendants, Gabriel Kimiaie-Asadi Bildstein and Abdel-Hakim El Ahmadi, remained at large in France.

The rest of the year passed comparatively quietly. ShinyHunters' output of new, confirmed breaches dropped sharply across 2022. It is a slowdown we could attribute to the combined weight of the indictment, Raoult's arrest and the loss of RaidForums as a home base. Rather than running a fresh breach spree, the group appears to have maintained a forum presence while mostly recirculating or reselling older data.

2023: Transition to forum operator

Timeline of major ShinyHunters-related events in 2023, including arrests and guilty pleas, the seizure and relaunch of BreachForums, a revealed business model, and alleged Pizza Hut data incidents.

ShinyHunters 2023 activity timeline: key events and operations

That year was still dominated by legal fallout and forum infrastructure. Nevertheless two developments pushed the story in a new direction. First, ShinyHunters stopped being merely a forum user and became a forum operator, co-relaunching BreachForums after its founder's arrest. It signed a structural shift that would set the stage for the following year's “mega breach”. Second, the group notched at least one confirmed, original breach of its own that year, showing the underlying data theft operation hadn't gone dormant even as its members faced prosecution. It's worth sitting with the ambiguity this created. By 2023, "ShinyHunters" simultaneously refers to a specific charged individual (Raoult, by now in US custody), a brand attached to breach claims, and an administrator handle on BreachForums. It wasn’t necessarily the same actor behind every use of the name. This is also the year claim inflation becomes a recurring pattern, with the group's public numbers starting to diverge from what victim companies ultimately confirm.

2023 opened with the legal case advancing. In January, Sébastien Raoult was extradited from Morocco to the United States and arraigned in Seattle on a nine count indictment. He initially pleaded not guilty. The indictment also named his co-conspirators.

Then, in March, the forum ecosystem took a direct hit. On the 15th, the FBI arrested "Pompompurin", founder and administrator of BreachForums,  in New York and charged him with conspiracy to commit access device fraud. Then, around the 21st, the forum's remaining administrator "Baphomet" took the site offline, fearing the infrastructure itself had been compromised. BreachForums v1 was effectively dead.

However, it didn't stay dead for long. In June, ShinyHunters partnered directly with Baphomet to relaunch the forum (commonly referred to as "v2") with the handover confirmed via a message signed with PGP from Baphomet. This marked ShinyHunters' shift from seller to administrator of the primary English speaking breach marketplace. This instance run by ShinyHunters would operate from June 2023 through May 2024. The same month, in a reminder that pressure on the ecosystem hadn't let up, the FBI, DOJ, and HHS-OIG seized several of the earlier BreachForums domains under a Virginia warrant issued June 23. The legal and the forum track then briefly converged in July, when Raoult reversed his earlier plea and pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft. Pompompurin, coincidentally, pleaded guilty in his own separate case that same month.

September brought the year's clearest evidence that ShinyHunters was still actively breaching companies. The group, operating under the handle "Shiny" (@shinycorp), claimed to have stolen more than 30 million order records and over a million customers' data from Pizza Hut Australia, gained via multiple misconfigured AWS S3 buckets with initial access dating back to around July or August. They claimed to have gone undetected throughout and demanded $300,000 to delete the data. Pizza Hut Australia confirmed a "cyber security incident" and notified customers around September 20, but scoped the impact to roughly 193,000 customers. The gap between the group's claimed figures (1M+ customers, 30M+ records) and the company's confirmed number (~193K) is worth flagging explicitly, as it's an early, clean example of the claim inflation that becomes a recurring feature of the group's later activity.

That same month, the DOJ's own paperwork offered a rare look inside the group's business model, all validated by the court. The announcement of Raoult's plea revealed that ShinyHunters had sold at least one company's stolen data repeatedly. A victim referred to as "Victim-4" in the report, was sold thirteen separate times at $5,000 each, netting $65,000 from a single dataset. The filings also confirmed the group extorted some victims for ransoms as large as $425,000. Moreover, when their intrusions reached a victim's cloud infrastructure, they sometimes used the victim's billed compute power to mine cryptocurrency on the side.

2024: The Snowflake campaign

Timeline of major ShinyHunters-related events in 2024, including the seizure and relaunch of BreachForums, Snowflake-related data theft campaigns, Ticketmaster data leaks, arrests, and indictments.

ShinyHunters 2024 activity timeline: key events and operations.

This is the year ShinyHunters became a genuine major threat. The year the brand's name reached an entirely different order of magnitude. The Snowflake campaign itself is the single largest event in the group's history, in which roughly 165 organizations were compromised through stolen credentials against cloud accounts that lacked multi-factor authentication. And a cycle of seizures and recoveries around BreachForums that cemented ShinyHunters' role as the forum operator rather than just another user.

Before going further, a critical attribution nuance is worth stating plainly. The Snowflake intrusions themselves are tracked by Mandiant under the designation UNC5537, and the individuals eventually charged for them (Connor Riley Moucka and John Erin Binns) are not part of the historic ShinyHunters core responsible for the 2020 to 2023 breaches. In this campaign, "ShinyHunters" functioned largely as a brand, a data broker and an extortion “megaphone”, overlapping with related personas like Sp1d3r, Sp1d3rHunters, SpidermanData and whitewarlock. Reporting on Snowflake tends to blur ShinyHunters, UNC5537, the “Sp1d3r” personas, Scattered Spider and the broader loose collective known as "The Com" together. Understandably, given how entangled their infrastructure and personas were, but it's a distinction worth holding onto. The people doing the hacking and the brand doing the extorting were not necessarily the same people.

The year opened with the closing of an old chapter. In January, Sébastien Raoult was sentenced in the Western District of Washington to three years in prison and over $5 million in restitution. 12 months tied to the wire-fraud conspiracy charge, the remainder for aggravated identity theft, plus 36 months of supervised release afterward. Prosecutors described his motive as simple greed and noted, notably, that he hadn't been a top figure within the organization. It's a fitting bookend. The first criminal chapter of ShinyHunters closed just as the brand was about to explode into something far bigger.

That explosion began gradually in April, with the Snowflake intrusions themselves. AT&T's environment, for instance, was accessed between April 14 and 25. The method was straightforward but devastating at scale. Credentials harvested by infostealer malwares, some of it valid since as far back as 2020, were used to log into Snowflake customer instances that lacked MFA. Snowflake's own platform was never breached, the vulnerability sat entirely on the customer side. The attackers used a custom reconnaissance and exfiltration tooling nicknamed "RapeFlake" to move through compromised environments. 

May brought both a major forum disruption and the campaign's first big public extortion plays. On May 15, the FBI and international partners seized BreachForums v2, the instance ShinyHunters had operated since June 2023, replacing it with a seizure notice and taking down the associated Telegram channel as well. The takedown barely slowed things. Within a day, ShinyHunters regained control of a domain (breachforums[.]st) and redirected users back, blunting the operation's impact almost immediately. Days later, on May 27-28, the user "SpidermanData" on the forum Exploit, followed by ShinyHunters on BreachForums, advertised 560 million Ticketmaster records (1.3TB) for roughly $500,000. It was timed, notably, to coincide with BreachForums' clearnet reactivation. Live Nation later confirmed unauthorized activity in an SEC filing. Then, on May 30-31, ShinyHunters mirrored a Santander breach originally posted by "whitewarlock," covering staff data and roughly 30 million customers across Spain, Chile, and Uruguay, listed for about $2 million. The actor also claimed the intrusion had come through the angle of a Snowflake employee, a claim that Snowflake disputed. Instead, they attributed the incident to poorly secured customer accounts.

By June, the true scale of the campaign came into focus. Mandiant published findings that up to 165 Snowflake customer organizations had potentially been exposed. Downstream victims named across reporting included Advance Auto Parts (with a claimed 380 million profiles and 3TB of data), LendingTree/QuoteWizard, Neiman Marcus, Bausch Health, and the Los Angeles Unified School District, among others. Much of the extortion during this period was driven by the "Sp1d3r" persona on BreachForums, often at prices researchers considered implausibly inflated.

The campaign's most consequential single disclosure happened in July. On the 12th, AT&T revealed that call and text metadata for approximately 110 million customers (essentially its entire wireless subscriber base, plus some MVNO and landline accounts) had been downloaded from its Snowflake workspace, with the stolen records spanning mostly May through October 2022. The Department of Justice had twice authorized a delayed public disclosure on national security grounds, given that call detail metadata of this kind can expose the contacts of government and military officials. AT&T reportedly paid around $370,000 (roughly 5.7 BTC at that time) to have the data deleted, with a researcher known as "Reddington" brokering the transaction. In exchange, the actor (linked to ShinyHunters and John Erin Binns) provided a video as proof of deletion. Around July 4, the same actors also re-escalated their Ticketmaster extortion, claiming Live Nation had rejected an earlier $1 million offer and demanding as much as $8 million instead, while a wave of parallel leaks dubbed "Celebrity Leak Week" included data such as Taylor Swift ticket barcodes.

The campaign's first arrest came in October. On October 30, Connor Riley Moucka, known online as "Judische," "Waifu," and "catist", was arrested in Kitchener, Ontario, on a US provisional warrant. He was assessed by investigators as a primary operator of the Snowflake data theft campaign. He had reportedly told the outlet 404 Media he expected to be arrested and was in the process of destroying evidence at the time.

The DOJ made the case formal in November. On November 11-12, an unsealed indictment charged both Moucka and Binns over the Snowflake campaign, alleging billions of records stolen from more than ten organizations and roughly $2.5 million (about 36 BTC) extorted from at least three victims between November 2023 and October 2024. The indictment's "Victim-2", described as a major US telecom breached around April 14, aligns with AT&T. John Erin Binns (“IRDev”), separately linked to the 2021 T-Mobile breach, had already been arrested in Turkey back in May 2024. Both men are tightly connected to “The Com”.

2025: Salesforce, vishing and Scattered Lapsus$ Hunters 

Timeline of major ShinyHunters-related events in 2025, including BreachForums activity, arrests, Salesforce-focused phishing and token-theft campaigns, infrastructure seizures, extortion activity, and major data breaches.

ShinyHunters 2025 activity timeline: key events and operations.

Two structural shifts define that year, with the first being a change in their tradecraft. The group's methods moved from credential theft against platforms like Snowflake toward a focus on social engineering like with Salesforce. Vishing combined with OAuth abuse before pivoting again toward SaaS supply-chain token theft, exemplified by the Salesloft Drift campaign. The second is a brand merger: ShinyHunters, Scattered Spider (tracked separately as UNC3944), and Lapsus$ coalesced publicly into a single collective calling itself "Scattered Lapsus$ Hunters" (SLSH), also referred to as the "Trinity of Chaos".

It's worth holding onto the same attribution caution that applied to 2024, because it only sharpened further that year. Google's threat intelligence tracks the individual pieces of this campaign as distinct clusters. 

  • UNC6040 for the vishing intrusions, 
  • UNC6240 for the extortion arm that "consistently claims to be ShinyHunters",
  • UNC6395 for the separate Salesloft Drift campaign, which Google explicitly did not attribute to ShinyHunters but is closely related to SLSH. 

In practice, when a report says "ShinyHunters did X" in 2025, it almost always means the “ShinyHunters extortion brand and data broker monetized X”. Not that a single, consistent team executed it end to end. By this point, "ShinyHunters" functions as a marketing brand and a role rather than a fixed roster, with a rough division of labor across the merged collective. 

  • Scattered Spider handles initial access through helpdesk social engineering, 
  • Lapsus$ contributes amplification and insider recruitment,
  • ShinyHunters handles data exfiltration, extortion, and data-leak-site (DLS) branding. 

Despite a growing string of arrests throughout the year, the collective kept operating. It showed a clear demonstration of how decentralized and resilient this ecosystem has become.‍

Nuances brought by InsideDarknet
Very interesting interviews conducted by Inside Darknet to ShinyHunters, LAPSUS$ and Hassan (a threat actor and current owner of BreachForums) bring some nuances to what Scattered Lapsus$ Hunters really is. According to ShinyHunters, they are not affiliated to SLSH and it would be Hellcat behind the scenes. LAPSUS$ also claims to have nothing to do with SLSH. So, could SLSH be related to the “larping” made by the French community after the shutdown of BreachForums, that Hassan is claiming?

Collage of excerpts from interviews conducted by Inside Darknet, discussing SLSH and its relationship with LAPSUS$ and ShinyHunters.

Various interviews conducted by Inside Darknet mentioning SLSH

The year's first major event was an arrest adjacent to the core group. In February, French authorities arrested Kai West, a 25-year-old British national behind the "IntelBroker" username and a BreachForums owner/administrator from August 2024 to January 2025. The arrest came just days after he'd posted his resignation from the forum. IntelBroker sat adjacent to ShinyHunters but was central to the same forum ecosystem. The arrest wasn't made public until June.

In April, BreachForums went dark again, this time abruptly and for uncertain reasons. Administrators blamed a MyBB zero-day vulnerability. Others pointed to a Dark Storm DDoS attack or retaliation from the Qilin ransomware group. Rumors of law enforcement involvement circulated as well. The true cause remains unsettled.

May brought two very different but equally telling incidents. Matthew D. Lane, a 19-year-old from Massachusetts, was charged with hacking and extorting an edtech provider widely identified as PowerSchool, using stolen contractor credentials to access data on tens of millions of students and teachers and demanding roughly $2.85 million in Bitcoin. The underlying breach had actually occurred back in December 2024, with affected school districts extorted again well into 2025. He will later plead guilty on June 6. Around the same time, Coinbase disclosed a breach in which overseas support contractors were bribed to access internal systems and customer data. A clean, documented example of the group's insider recruitment playbook.

The vishing campaign started in June. On the 4th, Google's GTIG published a report on the Salesforce vishing campaign it tracked as UNC6040/UNC6240. Attackers impersonated IT support staff over the phone, talked employees through authorizing a malicious OAuth connected application. It was a rebranded version of Salesforce's own Data Loader tool, disguised under names like "My Ticket Portal". Upon authorization, they exported data in bulk via the API. Google confirmed its own corporate Salesforce instance had been hit, exposing SMB advertising contact data. Through June and into July, an aviation sector wave unfolded, targeting Qantas, Air France-KLM, Hawaiian Airlines, WestJet, and later Vietnam Airlines, prompting a public warning from the FBI to the sector. BreachForums itself relaunched as "v4" around June 4 under ShinyHunters management, only to be posted as "closed / for sale" for $2,500 just five days later, on June 9.

That same month brought a plethora of law enforcement actions. On June 23, France's BL2C cybercrime unit arrested four suspects using the handles ShinyHunters (“YuroSH”, “Hollow”, “Noct”, and “Depressed”) spread across the Paris region, Normandy and Réunion, tied to BreachForums administration and breaches of Boulanger, SFR, France Travail, and the French Football Federation (FFF). On June 25, the DOJ's Southern District of New York unsealed charges against Kai West over the IntelBroker username, alleging roughly $25 million in damages across 41 paid sales and 117 free distribution offers between 2023 and 2025. 

The scale of damages from the vishing wave was confirmed in July. Qantas confirmed a breach affecting between 5.7 and 6 million customers, while Allianz Life confirmed exposure of the majority of its roughly 1.4 million customers. Reporting indicated Qantas allegedly paid around 4 BTC (roughly $400,000). The same phishing infrastructure was also used to target LVMH brands (Louis Vuitton, Dior, and Tiffany & Co) as well as Adidas.

August marked the emergence of the "Scattered Lapsus$ Hunters" identity, alongside a second major supply-chain campaign that would come to dominate the rest of the year. On the 5th, Google disclosed its own Salesforce breach, with Chanel and Pandora disclosing similar incidents. Then, between August 8 and 18, a separate campaign tracked as UNC6395 unfolded. Attackers who had compromised Salesloft's GitHub repository between March and June pivoted into Drift's AWS environment, then used stolen Drift OAuth tokens to export Salesforce data from more than 700 organizations. ShinyHunters itself claimed the number was closer to 760. It included Cloudflare, Zscaler, Palo Alto Networks, Proofpoint, Tanium, and PagerDuty, hunting specifically for embedded secrets like AWS keys, Snowflake tokens, and passwords. Salesloft and Salesforce revoked all Drift tokens on August 20, and Salesforce pulled Drift from its AppExchange marketplace entirely.

The merger itself became visible on August 8, when a Telegram channel appeared uniting Scattered Spider, Lapsus$ and ShinyHunters under the "Scattered Lapsus Hunters" name, promoting a forthcoming Ransomware-as-a-service (RaaS) offering dubbed "shinysp1d3r". Insider recruitment posts followed on August 31. It's worth repeating the attribution caveat here too. Google did not tie UNC6395 to ShinyHunters. Yet, SLSH monetized the stolen data regardless of who actually stole it.

September brought both official confirmation and a retirement announcement. On September 12, the FBI issued a FLASH alert (CSA-2025-250912) formally linking the Salesforce campaign wave to UNC6040 and UNC6395, publishing indicators of compromise including Mullvad VPN IPs, Tor exit nodes, and suspicious User-Agent strings. Then, on September 17, SLSH announced it was "going dark" and retiring. A claim quickly assessed by researchers as theatrics. A "goodbye letter" appeared on a freshly registered domain, breachforums[.]hn, which Resecurity flagged as likely disinformation rather than a genuine farewell.

The campaign's extortion climax happened in October, followed immediately by another forum seizure. On October 3, SLSH launched a dedicated Salesforce data leak and extortion site (DLS) listing between 39 and 40 brands. It included FedEx, Disney/Hulu, Home Depot, Marriott, Toyota, McDonald's, IKEA, UPS, TransUnion, Qantas, Chanel, Adidas, Cisco, Google AdSense, Stellantis, Saks, and Air France-KLM. They were claiming roughly one billion records in total and demanding payment from both Salesforce and each individual victim by October 10. The group even invited plaintiff law firms to "cooperate" with the extortion. Salesforce publicly refused on October 8, stating it would "not engage, negotiate with, or pay". 

Just a day or two later, on October 9-10, US and French authorities seized the BreachForums infrastructure being used to run the extortion site. ShinyHunters responded by publicly "walking away," declaring the remaining BreachForums domains a law enforcement honeypot and leaking the forum's own user data as a parting shot.

November closed the year with signs the group was still evolving its toolkit rather than genuinely retiring. A follow-on campaign abusing Gainsight OAuth tokens affected more than 200 additional Salesforce instances, prompting Salesforce to revoke the related OAuth access. The same SaaS integration playbook seen with Drift. Meanwhile, the shinysp1d3r RaaS platform teased back in August was reported to be in active development. The group's first real move toward ransoms based on encryption. This might be seen as an attempt to fill the void left by LockBit's decline? 

2026: Zero-day adoption, supply-chain pivots & ransomware 

Timeline of major ShinyHunters-related events in 2026, including data breaches, phishing and token-theft campaigns, threats against executives, BreachForums activity, ransom demands, and a guilty plea linked to Snowflake attacks.

ShinyHunters 2026 activity timeline: key events and operations.

By 2026, the entity operating under the ShinyHunters name is best understood as Scattered Lapsus$ Hunters (SLSH). Google tracks the live intrusion clusters behind that year's activity as UNC6661 and UNC6671, both centered on vishing and SSO compromise, with UNC6240 continuing to serve as the branded extortion arm “ShinyHunters” that claims credit for the resulting data. The group is still using vishing to pivots through enterprise SSO providers (Okta, Entra, Google) into SaaS platforms like SharePoint, OneDrive, Salesforce and Slack. They are systematically scanning for misconfigured Salesforce Experience Cloud (Aura) deployments and SaaS supply-chain token theft, running from Drift through Gainsight to Anodot. There were also two escalations that year worth tracking separately from breaches. A turn toward violent coercion, with statements that SLSH added physical threats against executives, DDoS attacks, and swatting to its extortion toolkit. And the long promised shinysp1d3r ransomware moved from concept toward a functional, tested payload, without any victims as of mid-2026 however. As with the previous year, a substantial amount of unverified claims and outright impersonation continues to muddy the record throughout the year.

It opened with a sign of fracture inside the ecosystem itself. On January 9, a self-identified former ShinyHunters member using the name "James" (or "James Mathis") repurposed a domain linked to ShinyHunters to publish a 23 pages manifesto doxxing BreachForums administrators and users, alongside a leaked forum metadata database of roughly 324,000 records. An act of internal betrayal that suggested real strain within the collective.

Operationally, the vishing campaign tracked as UNC6661/UNC6671 was already underway, targeting enterprise SSO providers (Okta, Microsoft, and Google) through IT helpdesk impersonation and phishing portals tailored to victims. Once inside, the attackers exfiltrated data from SharePoint, OneDrive, Salesforce, and Slack, and abused a Gmail add-on called ToogleBox Recall to delete MFA enrollment alerts and cover their tracks. Panera Bread (roughly 5 million records, via a compromised Microsoft Entra SSO) and Grubhub both surfaced as extortion targets that month. The group's Salesforce Experience Cloud tooling, built around a modified version of the open-source auditing tool AuraInspector, released that same January and immediately got weaponized.

February's headline breach was Wynn Resorts, which ShinyHunters listed on its leak site claiming over 800,000 records of employee data and demanding 23.34 BTC (roughly $1.55 million) with a deadline dated to February 23. A group member told The Register that access had actually been gained back in September 2025, via an Oracle PeopleSoft vulnerability exploited using a stolen employee credential. The Okta SSO campaign also claimed Figure Technology Solutions (~1 million records) and Dutch telecom Odido had roughly 6 million accounts leaked. In September 2026, in the program “Opsporing Verzocht”, the conversation with the suspected caller in this Odido hack was released publicly on TV. The caller was posing as a colleague from IT and was conducting live vishing, collecting both credentials and MFA SMS code, while having a native Dutch accent and excellent technical knowledge.

Krebs on Security reported that month on the operational merger of ShinyHunters, Scattered Spider, and Lapsus$ into SLSH, explicitly noting the collective's escalation toward physical violence threats against executives, DDoS attacks, and swatting as extortion tools.

The Aura campaign moved into full swing in March, with the group mass scanning for misconfigured Salesforce Experience Cloud guest user profiles carrying excessive API permissions, using their modified AuraInspector tool. Salesforce itself confirmed the activity as the work of a known threat group rather than a platform vulnerability. The group claimed roughly 100 affected companies, though later reporting suggests the true sweep reached closer to 400, naming Snowflake, Okta, LastPass, and Salesforce itself among the affected ecosystems. The European Commission confirmed a cloud data breach involving roughly 350GB of data, reportedly hosted on AWS infrastructure, though AWS maintained its own services had not been compromised. The telecom provider Telus faced a claimed theft of roughly one petabyte of data alongside a reported $65 million ransom demand. Infinite Campus, an education platform, was hit through Salesforce, and extortion against Rockstar Games began that month via what would later be identified as the Anodot compromise.

April brought the year's current signature supply-chain event. ShinyHunters stole authentication tokens from analytics provider Anodot and reused them to pivot directly into customers' Snowflake and BigQuery environments, reportedly affecting dozens of companies. The confirmed downstream victims included:

  • Rockstar Games with a claimed 78.6 million records. An ultimatum was issued on the 11th with a deadline of April 14 deliberately timed around the anticipated GTA VI announcement window.
  • Vimeo, with roughly 119,200 emails exposed and about 106GB leaked after extortion negotiations failed. 
  • Zara/Inditex, with roughly 197,000 records affected. 

On April 14, McGraw-Hill confirmed a breach stemming from a Salesforce misconfiguration. ShinyHunters claimed up to 45 million records, though the company characterized the exposed data as limited and nonsensitive. ADT was hit as well with a straightforward pay-or-leak threat covering roughly 5.5 million records. And around April 25, the initial compromise of Instructure's Canvas platform occurred, exploiting the "Free-For-Teacher" account creation mechanism. An intrusion that would explode into one of the year's largest incidents the following month.

Indeed, the Canvas compromise became public on May 3, when ShinyHunters claimed 275 million records and 3.65TB of data across 8,809 educational institutions. Instructure confirmed unauthorized access later on. The situation escalated sharply from there. After Instructure declared the incident resolved, the group compromised Canvas again on May 7 and defaced roughly 330 university login portals, including Harvard, Penn, Duke, and Wisconsin, during finals week, attaching a new deadline of May 12. Around May 12, Instructure reportedly paid the ransom and reached an agreement with the group to delete logs of the stolen data. During the same period, Carnival Cruise Line had roughly 6 million passenger records exposed, Charter/Spectrum around 4.9 million, DentaQuest about 2.6 million with hundreds of gigabytes published, and insurer Kemper roughly 13 million.

June's defining event was the industrialization of the Oracle PeopleSoft attack vector, most likely the same as the one used against Wynn Resorts back in February. Google's Threat Intelligence Group identified an active compromise and extortion campaign, attributed to ShinyHunters, exploiting CVE-2026-35273. It is a critical CVSS 9.8 remote code execution vulnerability in PeopleSoft's Environment Management component (PSEMHUB) endpoint. The activity ran from May 27 through June 9, predating Oracle's own security advisory on June 10, meaning it was exploited as a genuine zero-day.

Google identified over 100 exposed organizations globally through IP correlation and proactively notified them before the campaign became public. Roughly 68% of the affected organizations were in higher education. The campaign came fully into view after a security researcher publicized open, unsecured attacker staging directories, allowing Google to reconstruct the operation in detail. The attackers had built their staging infrastructure around the open-source MeshCentral remote management platform, deploying Windows agent binaries disguised as Microsoft Azure services and configured to communicate with a C2 domain designed to mimic legitimate Azure infrastructure. From there, they conducted targeted reconnaissance inside compromised PeopleSoft environments, mapping configuration files and internal network topology, before writing a custom lateral movement script to each victim. This script attempted SSH access across internal hosts and deployed a defacement file as proof of compromise. Stolen data was compressed and exfiltrated before the attackers connected out to the infrastructure hosting the public ShinyHunters data-leak site. The campaign correlated directly with a wave of new victim postings on that site on June 9.

In May, Beazley Security’s DFIR team assisted with a breach that was eventually confirmed to be an instance of this Oracle PeopleSoft attack wave. This revealed some more TTPs and tooling leveraged in the campaign. ShinyHunters was observed deploying small JSP backdoors on compromised PeopleSoft servers to maintain persistence. Lateral movement was achieved mostly through RDP with compromised credentials, though other attacks like Pass-the-Hash were also observed. Open source network tunnel utility Chisel was used to facilitate remote RDP sessions. Many hosts had malicious scheduled tasks executing obfuscated PowerShell scripts, and many of those hosts had PowerShell monitoring disabled. Attacks against security tools also included a small windows script that disables CrowdStrike EDR. MeshAgent was observed being used as C2, matching Google’s reporting. The popular open source file transfer utility Rclone was used when exfiltration was attempted.

Beyond PeopleSoft, June also brought a string of other confirmed and claimed victims: Kodak, with roughly 2.2 million records threatened, Amazon's One Medical listed with a claimed 8.8TB of data. Also, the Council of Europe which had 297GB of employee data covering more than 10,000 employees and contractors published after a missed ransom deadline. Additionally, the NAIC, the US insurance regulator, with a claimed 3.1TB exposure.

July’s most significant claims were RingCentral and Ernst & Young. The first one occurred in July via social engineering and they were added to the data leak site in late July claiming over 623 GB of data, eventually publishing a 280 GB archive affecting roughly 1.6 million customers. For Ernst & Young, on July 27, ShinyHunters publicly claimed responsibility for a breach EY had already disclosed to state Attorneys General, alleging it obtained credentials via a supply-chain compromise of an unnamed third party and pivoted into EY's Jira, GitHub, and Azure environments through a third-party IT service management platform used for tax support tickets. EY's own investigation found unauthorized access occurred between March 28 and April 12, 2026, with detection on April 23. They gave EY an extortion deadline that would expire on July 31.

In August, Connor Riley Moucka pleaded guilty as part of the Snowflake campaign. There was also a concentration of heavy claims. CyrusOne, a US data center provider (serving Microsoft, Meta, etc…), was named on the 23rd, with claims of 12.9 million Salesforce records, 600+ GB of SharePoint data and extensive facility/security documentation. Next, between the 22nd and 25th, ReliaQuest got breached with a vishing and lookalike SSO campaign, where it briefly yielded an authenticated identity dashboard session before being contained. A claim the vendor disputed as limited to view-only access to one identity. Finally, McKesson between the 25th and 28th, the month's headline incident, in which the healthcare distributor confirmed unauthorized access to third-party applications affecting its Oncology and medical surgical units. ShinyHunters claimed 284 million patient records exfiltrated and demanded $55,236,150. The month closed with Neogen Corporation listed on the 30th, with telemetry suggesting a compromised employee Okta credential had been active since early June. 

In the beginning of September, ShinyHunters claimed to have compromised the Florida Department of Motor Vehicles and leaked the records and driver license of Jeffrey Epstein as a proof of their compromise. 

Victimology

Infographic summarizing ShinyHunters victimology by targeting model, geography, targeted platforms, and data types, highlighting shared platform exploitation, monetizable data, extortion leverage, and shifting targets from cloud services to Snowflake, Salesforce, and identity integrations.

ShinyHunters victimology overview

Unlike state sponsored actors pursuing intelligence value or ideologically motivated hacktivists, ShinyHunters' targeting has remained consistently financial through the years. The group is opportunistic rather than strategic. It doesn't pick targets for who they are, but for what they expose. 

Targeting model

The dominant, by far, is exploitable shared platform. Whoever happened to run misconfigured S3 buckets in 2020, unprotected Snowflake instances in 2024 or vulnerable Oracle PeopleSoft deployments in 2026 became, by definition, the victim pool for that period. This filter moves constantly, and tracking it over time is really tracking the group's technical evolution rather than any strategic pivot.

Then, it is a monetizable data volume. Whether a target holds enough PII to make resale or extortion worth the effort. A breach yielding a few thousand records rarely surfaces publicly. The group's economics depend on scale.

Finally, it is extortion leverage. Whether a leak would expose the victim to regulatory consequences under frameworks like GDPR, CCPA, HIPAA, FERPA or to reputational and litigation risk severe enough to make paying look cheaper than not paying. This is why healthcare, education, and financial services victims recur so often. The compliance exposure does much of the group's negotiating for it.

Geography

Geographically, ShinyHunters has never targeted any particular country, but its footprint has shifted twice.

In the group's earliest period, 2020-2021, there was a notable weighting toward APAC, India, and Indonesia. Such targeting includes victims like Tokopedia, Unacademy, BigBasket, Juspay, Upstox, and RedDoorz as aforementioned. This wasn't a deliberate regional strategy but rather a byproduct of opportunism. Many of these organizations had weak data hygiene, including plaintext or MD5 hashed password storage that the group openly mocked in its own leak posts.

From 2024 onward, it moved decisively toward the United States, Western Europe, and Australia. A shift that tracks almost perfectly with the customer bases of Snowflake, Salesforce, Okta, and Drift, which skew heavily toward Western enterprise. In other words, the geography changed because the platforms changed, and those platforms happen to be sold predominantly to Western companies.

One location deserves a specific note however: France. Several of the core operators are French nationals. And when French law enforcement arrested members in 2025, the victims tied to those specific individuals were disproportionately French entities: Boulanger, SFR, France Travail, and the French Football Federation among them. It's one clear case where the operators' own nationality, rather than platform economics, appears to have shaped victim selection.

Targeted platforms

The targeted platform is best understood as a rolling target of opportunity that has shifted roughly once a year:

  • 2020-2021: anyone exposing GitHub OAuth tokens or misconfigured AWS S3 buckets.
  • 2024: any Snowflake customer running without MFA.
  • 2025: any Salesforce customer whose staff could be socially engineered into authorizing a malicious OAuth application, plus any organization integrated with Salesloft Drift.
  • 2026: anyone connected through Gainsight or Anodot integrations, running a misconfigured Salesforce Experience Cloud (Aura) deployment, relying on Okta or Entra for SSO, or operating a vulnerable Oracle PeopleSoft instance.

Each pivot marks the same pattern. One access channel gets exhausted and the group moves on to the next platform whose weaknesses are both exploitable at scale and worth the effort. 

Data types

What the group actually takes falls into two distinct categories, serving two different purposes.

The primary target is data suited for direct resale or extortion: names, emails, phone numbers, physical addresses, dates of birth, hashed or plaintext passwords, partial payment card numbers and order, loyalty or enrollment histories. This is the data that shows up in the leak site listings and drives ransom demands.

The secondary target is data suited for pivoting into the next intrusion rather than immediate sale. Embedded secrets such as AWS keys, Snowflake tokens, VPN credentials and API keys, often harvested from support tickets and CRM notes. This category is arguably more strategically important than the primary one since it's what allows one breach to seed the next. Such a pattern was especially visible in the Salesloft Drift to Gainsight to Anodot chain across 2025/2026.

Notably absent from the group's interests is anything with pure intelligence value rather than financial value. Trade secrets and information sought for competitive advantage, classified material or data useful primarily for surveillance rather than resale.

Conclusion

Six years on, ShinyHunters is less a group than a brand and business model that has outlived its founders. What began in 2020 as a small crew trading stolen databases on RaidForums has become a persistent, self-renewing group that has absorbed indictments, arrests, and forum seizures without ever going quiet for long. Members have been extradited, convicted, and sentenced. Entire pieces of infrastructure have been dismantled by the FBI, DOJ, and Europol. But each time, the name resurfaces within weeks, attached to a new cluster of operators exploiting a new platform.

That resilience is the real story. It doesn't come from any single leader or cell, but from a division of labor that has become almost modular: initial access from social engineers, amplification and recruitment from adjacent actors, and monetization under a shared, recognizable brand. The formation of Scattered Lapsus$ Hunters in 2025 made that structure explicit. But the pattern was visible years earlier, in the gap between Snowflake's "ShinyHunters" and the operators later charged under names like UNC5537. The brand persists independently of the people behind any individual breach, which is precisely what makes it so hard to kill and so easy to over-attribute to.

The technical throughline is just as consistent as the organizational one. Each year the group has been defined by whichever authentication or access gap was cheapest to exploit at scale: 

  • Exposed GitHub tokens and S3 buckets in 2020. 
  • MFA-less Snowflake accounts in 2024. 
  • OAuth-abused Salesforce integrations in 2025. 
  • Zero-day exploitation against Oracle PeopleSoft alongside a widening SaaS supply chain running through Drift, Gainsight, and Anodot by 2026. 

The common denominator is trust relationships between platforms and the group's evident willingness to weaponize whatever the current one happens to be.

What should concern defenders going into the rest of 2026 isn't a single new TTP but where the group is headed. From data theft toward encryption with shinysp1d3r ransomware, and from financial pressure alone toward physical threats, DDoS, and swatting. An actor that has spent six years treating extortion as a business is now visibly experimenting with harder forms of coercion.

Whether "ShinyHunters" in twelve months' time refers to any of the people discussed in this report is almost beside the point. The name has already outgrown its original members. The question worth asking isn't who is behind the next breach. It is which platform's trust model they'll exploit next, and whether the industry will close that gap faster than the group can find it.

Detection & tracking opportunities

These queries can be used to hunt in your telemetry using the Sekoia Operating Language (SOL) as part of Sekoia’s AI SOC platform. 

CrowdStrike disable script

events 
  | where timestamp > ago(30d) 
  | where file.path == "C:\\Windows\\Temp\\.bea-cache\\cs_disable.cmd"  
    or process.command_line contains "cs_disable.cmd"
    or file.name == "cs_disable.cmd" 
  | select timestamp, host.name, user.name, process.name, process.command_line, file.path, file.name, event.action 
  | order by timestamp desc 
  | limit 100

Scheduled task creation “MeshFwFix”

events
  | where timestamp > ago(30d)
  | where (event.code == "4698" or event.action == "scheduled-task-created" or event.category == "scheduled_task")   
    and (process.command_line contains "MeshFwFix" or action.properties.TaskName contains "MeshFwFix" or message contains "MeshFwFix")
  | select timestamp, host.name, user.name, process.name, process.command_line, task.name, event.action
  | order by timestamp desc
  | limit 100

Malicious domain

 events
  | where timestamp > ago(90d)
  | where url.domain == "azurenetfiles.net" 
    or dns.question.name contains "azurenetfiles.net"
  | aggregate count=count(), first_seen=min(timestamp), last_seen=max(timestamp) by host.name, source.ip
  | order by count desc 

Malicious remote IP

events
  | where timestamp > ago(90d)
  | where destination.ip == "142.11.200.186" 
    or source.ip == "142.11.200.186"
  | aggregate count=count(), first_seen=min(timestamp), last_seen=max(timestamp) by host.name, destination.port
  | order by count desc

Modified MeshAgent binary

events
  | where timestamp > ago(30d)
  | where file.path == "C:\\Windows\\Temp\\ma.exe" 
    or process.executable == "C:\\Windows\\Temp\\ma.exe" 
    or process.command_line contains "\\Windows\\Temp\\ma.exe"
  | select timestamp, host.name, user.name, process.name, process.command_line, process.parent.name, process.parent.command_line, file.path, event.action
  | order by timestamp desc| limit 100

Webshell filenames

events
  | where timestamp > ago(30d)
  | where event.category == "file" and event.action in ["creation", "file_create", "created"] 
    and (file.name == "orau.jsp" or file.name == "webpack.jsp")
  | select timestamp, host.name, user.name, process.name, process.command_line, file.path, file.name, event.action
  | order by timestamp desc
  | limit 100

‍

IoCs & technical details

These are the IoCs related to a ShinyHunters Oracle PeopleSoft incident, observed and collected by Beazley Security during incident response. The filenames are clickable and link to our Gist, where the file contents are hosted. 

‍

Appendix

Aliases & related operations

Alias Description
UNC5537 Snowflake intrusions (2024)
UNC6040 Salesforce vishing intrusions (2025)
UNC6240 Extortion cluster consistently claiming the ShinyHunters name
UNC6395 Salesloft Drift intrusions (2025)
UNC6661 SSO/vishing intrusions (2026)
UNC6671 Vishing and SaaS data-theft cluster with overlapping TTPs
Bling Libra Unit 42's designation for ShinyHunters
Scattered LAPSUS$ Hunters The group claiming to be the association of Scattered Spider, LAPSUS$ and ShinyHunters

‍

Operators & adjacent personas overview

Person Username(s) Nationality Status Tied to
Sébastien Raoult Sezyo Kaizen FR 🇫🇷 Arrested Morocco May 2022.
Extradited Jan 2023.
Sentenced Jan 2024 (3 yrs, $5M+).
Core 2020-21 ShinyHunters
Gabriel Kimiaie-Asadi Bildstein Kuroi'SH FR Indicted 2021.
Not convicted.
Core 2020-21 ShinyHunters
Abdel-Hakim El Ahmadi Zac
Jordan Keso
FR Indicted 2021.
Not convicted.
Core 2020-21 ShinyHunters
Diogo Santos Coelho Omnipotent PT Arrested Jan 2022. RaidForums founder
Connor Riley Moucka Judische
Waifu
catist
CA Arrested Oct 30 2024.
Indicted Nov 2024.
Pleaded guilty on August 2026.
Snowflake UNC5537
John Erin Binns IRDev
j_irdev1337
US Arrested Turkey May 2024. Snowflake + 2021 T-Mobile.
Conor Brian Fitzpatrick Pompompurin US Arrested Mar 2023.
Sentenced to 20 years supervised release.
BreachForums founder.
Kai West IntelBroker UK Arrested France Feb 2025.
Indicted SDNY Jun 2025 (~$25M).
BreachForums "v3" owner.
Matthew D. Lane - US Charged May 2025.
Pled guilty Jun 6 2025
PowerSchool extortion.
Adel E. ShinyHunters
YuroSH
FR Arrested Jun 23 2025 (BL2C). BreachForums admin.
French breaches
Ziad M. Hollow
Trihash
FR Arrested Jun 23 2025 (BL2C). BreachForums admin.
French breaches
Thibault E. Noct FR Arrested Jun 23 2025 (BL2C). BreachForums admin.
French breaches
Yanis H. Depressed FR Arrested Jun 23 2025 (BL2C). BreachForums admin.
French breaches

Forum lineage

Timeline tracing the evolution of cybercriminal forums associated with ShinyHunters, from RaidForums through successive BreachForums versions and post-seizure activity between 2015 and 2026.

Chronological evolution of the cybercriminal forums that shaped ShinyHunters operations

Alleged comeback on social medias

In July 2026, an account under the handle “UNC6040” posted a message on RaidForums claiming to be back, alongside new social media handles (both on X and Telegram). Their X account quickly got suspended, despite trying to gain legitimacy by interacting with Kuroi’SH (@lizardcircles) under one of its posts. That being said, we noticed an interesting behavior on Telegram. The channel was created on the 19th of July, with a single message being posted by this “ShinyHunters”. However, on the 12th of August, the channel changed its handle to @Hackuten and was advertising a cybersecurity CTF platform. The original handle @ShinyHuntCorps was transferred to a newly created channel, on the 11th of August. 

Sekoia’s TDR team believes these actions were conducted by posers, trying to leverage ShinyHunters’s brand recognition for marketing purposes.

Collage of a RaidForums post and Telegram screenshots claiming ShinyHunters has returned, warning about impersonators, and showing related channels and community activity.

Alleged comeback of ShinyHunters on social networks

‍

Additional informations about SLSH by BreachForumsNews

In December 2025, @wokawoka10 posted “the truth about Scattered LAPSUS$ Hunters” on the Telegram channel @BreachForumsNews. In its message, the actor goes in-depth into ShinyHunters story, especially after the various arrests of the group’s members. According to him, no one can really make sense of what is going on anymore with ShinyHunters. Apparently, the ShinyHunters’s PGP key was handed over to Mattys Savoie, which from then, has been abused to cause chaos, clear reputation and perpetrate the group’s activity against the will of Hollow. These claims are followed by screenshots of Mattys’s leaked criminal records. Something to note is that they associate Hollow/Trihash with the name “Raphael” whereas Le Monde, associates the username with Ziad M. One theory could be that Hollow, for operational security reasons, had lied about his real identity by providing a fake name to partners.

Two screenshots of a BreachForumsNews Telegram post claiming to reveal the identity and activities of Scattered LAPSUS$ Hunters, including alleged impersonation, internal disputes, data theft, and extortion.

Screenshots of a message in the Telegram channel "BreachForumsNews" supposedly posting the truth about Scattered LAPSUS$ Hunters.

文章来源: https://www.sekoia.com/blog/gotta-breach-em-all-the-journey-of-shinyhunters
如有侵权请联系:admin#unsafe.sh