CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

ShinyHunters

actor · actor:shinyhunters single-source

Financially motivated data-theft and extortion group (also tracked as UNC6240) behind the 2026 Salesforce/SaaS victim cluster (Instructure, Vimeo, 7-Eleven, Carnival, Inditex/Zara, Medtronic and others) and the Oracle PeopleSoft data-theft campaign.

Aliases: UNC6240

Coverage
27
23 about it · 4 mentions · first 2026-05-06 → last 2026-09-27
Latest activity
2026-09-29
The FBI confirms ShinyHunters compromised its jobs portal; a Dutch arrest exposes an internal power struggle…
Peak priority
critical
1 critical · 11 high · 11 notable
Targets
public-sector
sectors: public-sector, technology, healthcare · regions: europe, us, uk
Sources cited
120
55 hosts
2026-05-0827 appearances2026-09-27

Action items (12)

Do-now tasks recorded on the entries about ShinyHunters, newest first. Check the date before acting on an older one.

  • Watch Oracle's own security-alert channel for an emergency PeopleSoft advisory in the coming days; any organization running an internet-facing PeopleSoft component, especially a recruitment or HR/jobs-portal instance matching the FBI's own claimed entry point, should treat unexplained PeopleSoft process activity or unusual outbound connections as a priority hunt lead until Oracle confirms or denies the claim.
    2026-09-24The FBI confirms ShinyHunters compromised its jobs…
  • Immediate action: UNC6240 (ShinyHunters) is again mass-exploiting CVE-2026-35273 against organisations that patched their WAF but not PeopleSoft itself, using a URL-encoded path (/%50SEMHUB/) that many WAFs match before decoding. Apply Oracle's Security Alert or disable/remove PSEMHUB; where a WAF is the only control, reconfigure it to block on the normalized path, not the literal string, and search WebLogic access logs for /PSEMHUB/ and any encoded or mixed-case variant (Mandiant/GTIG, 2026-09-25).
    2026-06-11CVE-2026-35273
  • Patch every Oracle PeopleSoft instance to a supported PeopleTools release or disable/remove PSEMHUB now (CVE-2026-35273); a WAF rule alone no longer stops this. UNC6240 (ShinyHunters) bypasses literal-string /PSEMHUB/ WAF blocks with the URL-encoded /%50SEMHUB/ path, so a perimeter block that has not been reconfigured to match on the normalized path is not a control. Treat any instance that was internet-reachable and unpatched at any point since 27 May 2026 as compromised until proven clean, and rotate every credential reachable from the PeopleSoft tier.
    2026-06-11CVE-2026-35273
  • Hunt for the post-exploitation toolkit on any PeopleSoft host. Search WebLogic access logs for /PSEMHUB/ and its encoded/mixed-case variants; scan PSEMHUB.war/PORTAL.war for unexpected .jsp/.jspx/.exe files (including Ple64.exe); check for MeshAgent/MeshCentral agents and SSH credential-spraying against hosts in /etc/hosts; and review for ransom-note markers in PeopleSoft directories.
    2026-06-11CVE-2026-35273
  • Audit Salesforce connected apps for unrecognized or over-privileged OAuth grants, specifically apps posing as legitimate integration tooling (e.g. a Data Loader lookalike) and any connected app inactive for 90+ days, and revoke them; this is the trust relationship the campaign abuses, and it is invisible to sign-in-anomaly detection.
    2026-07-14Microsoft maps a year of Salesforce OAuth abuse…
7 older action items
  • Block or tightly scope the Entra ID device-code authentication flow tenant-wide, ReliaQuest names this the single highest-impact control, because it neutralises the session-token capture regardless of how convincing the vishing pretext is.
    2026-07-10ReliaQuest: new 'Helix' extortion cluster…
  • Alert on a new MFA-authenticator registration occurring within minutes of a device-code sign-in from a residential-proxy IP the account has never used, that co-occurrence is Helix's persistence artifact and is otherwise indistinguishable from normal user activity.
    2026-07-10ReliaQuest: new 'Helix' extortion cluster…
  • Hunt SharePoint/Graph access logs for enumeration using contentclass:STS_Site and wildcard search queries at automation speed from a non-browser (python-requests) user-agent, followed by bulk downloads; the automated-collection stage is the most reliable fingerprint.
    2026-07-10ReliaQuest: new 'Helix' extortion cluster…
  • Reinforce helpdesk/customer-service verification: require out-of-band callback confirmation before any staff member authenticates in response to an inbound call claiming to be internal IT; the control that would have stopped both the Odido and the earlier tracked ShinyHunters vishing intrusions.
    2026-07-10Dutch police tie ShinyHunters' Odido telecom breach…
  • Alert on a single account performing a bulk export from a customer-contact or CRM repository shortly after an interactive sign-in from an unusual location; Odido's operators bulk-downloaded 6.2M records before the account was blocked within the hour.
    2026-07-10Dutch police tie ShinyHunters' Odido telecom breach…
  • Confirm CVE-2026-35273 (Oracle PeopleSoft PeopleTools) is patched and PeopleSoft PeopleTools is off the public internet; the ShinyHunters campaign is still acquiring named victims (Nissan).
    2026-06-28CVE-2026-35273
  • Patch SimpleHelp to 5.5.16 / 6.0 RC2, or disable OIDC, CVE-2026-48558 lets an unauthenticated attacker forge an OIDC token into a full Technician session and bypass IdP MFA; review access logs for no-signature token exchanges preceding successful Technician auth (.
    2026-06-13CVE-2026-48558

Defender insights

What each entry about ShinyHunters tells a defender to do, newest first.

2026-09-24HIGHThe FBI confirms ShinyHunters compromised its jobs portal; a Dutch arrest exposes an internal power struggle over the ShinyHunters brand

Latest update

2026-06-11CRITICALexploitedShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration

Detection

2026-07-18NOTABLEAbbott confirms unauthorized access to its Cancer Diagnostics (Exact Sciences) systems as ShinyHunters claims a helpdesk-vishing to Entra SSO breach

Latest update · triage

2026-07-19NOTABLEEY discloses client tax-data exposure after a third-party ITSM support-ticket platform was breached

Latest update

2026-07-14NOTABLEMicrosoft maps a year of Salesforce OAuth abuse (vishing consent, supply-chain secret reuse, guest-access Aura abuse) invisible to sign-in detection

Triage

2026-07-10HIGHReliaQuest: new 'Helix' extortion cluster (BlackFile/ShinyHunters lineage) vishes staff into device-code sign-ins, then bulk-loots SharePoint

Triage

7 earlier entries carry guidance too, listed under the story timeline below.

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

overlaps with

attributed activity

Story timeline

Every entry that names ShinyHunters, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.

  1. 2026-09-27Flink refuses a corporate ransom after an Order Hub breach, so extortion actor "LPG Group" pivots to crowdfund-style individual extortion of at least 10,000 customers and employees
    mentionactive-threatsA refused corporate ransom becomes 10,000+ individual shakedown emails: an extortion playbook worth recognizing before it recurs
  2. 2026-09-24ShinyHunters claims a breach of the FBI's own recruitment infrastructure via an unconfirmed Oracle PeopleSoft zero-day; the FBI now confirms the compromise itself while still investigating scope
    active-threatsThe FBI confirms ShinyHunters compromised its jobs portal; a Dutch arrest exposes an internal power struggle over the ShinyHunters brand
  3. 2026-09-20Oracle's September 2026 Critical Security Patch Update carries fifty unauthenticated CVSS 9.8+ flaws, concentrated in Fusion Middleware's identity, forms, directory and portal components, plus E-Business Suite, Hyperion, Analytics, Enterprise Manager, Communications and Supply Chain products
    mentiontrending-vulnerabilitiesFifty credential-free, no-interaction flaws span Oracle's middleware, ERP, BI and telco-assurance lines, more than triple this entry's original count
  4. 2026-08-28Troy Hunt: a 24.9M-address ShinyHunters/Carhartt breach-claim collapses to 12.9M real records once TPC-DS synthetic benchmark data and several duplicate/test-account patterns are filtered out, a reusable methodology for verifying inflated breach-claim record counts
    researchDomain-frequency, TLD and birth-year distribution analysis unmasks a benchmark dataset masquerading as half of a real breach
  5. 2026-07-19Ernst & Young discloses a breach of a third-party IT support-ticket platform used by its tax practice, exposing client tax and financial documents
    active-threatsEY discloses client tax-data exposure after a third-party ITSM support-ticket platform was breached
  6. 2026-07-18Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records
    active-threatsAbbott confirms unauthorized access to its Cancer Diagnostics (Exact Sciences) systems as ShinyHunters claims a helpdesk-vishing to Entra SSO breach
  7. 2026-07-16CVE-2026-46817, Oracle E-Business Suite (Payments): unauthenticated RCE now CISA KEV-listed after quiet in-the-wild exploitation (CVSS 9.8)
    mentiontrending-vulnerabilitiesOracle E-Business Suite Payments pre-auth takeover (CVE-2026-46817) confirmed exploited and KEV-listed, patch or pull exposed instances off the internet
  8. 2026-07-14Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers, none exploiting a Salesforce vulnerability
    researchMicrosoft maps a year of Salesforce OAuth abuse (vishing consent, supply-chain secret reuse, guest-access Aura abuse) invisible to sign-in detection
  9. 2026-07-10ShinyHunters' Odido (NL telecom) breach: Dutch police voice analysis points to Dutch-national involvement; same vishing-into-spoofed-portal playbook, now against an EU telco
    active-threatsDutch police tie ShinyHunters' Odido telecom breach to Dutch nationals via voice analysis, the vishing-to-spoofed-portal playbook now hits an EU telco
  10. 2026-07-10'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration
    active-threatsReliaQuest: new 'Helix' extortion cluster (BlackFile/ShinyHunters lineage) vishes staff into device-code sign-ins, then bulk-loots SharePoint
  11. 2026-07-03Medtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach, 2.5 months after containment
    active-threats
  12. 2026-07-01Oracle E-Business Suite CVE-2026-46817: pre-auth RCE in the Payments File Transmission servlet, first in-the-wild exploitation
    deep-dive
  13. 2026-06-28NAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pause
    active-threats
  14. 2026-06-27UK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach, 160 universities, ShinyHunters extortion, ransom paid
    active-threats
  15. 2026-06-26ShinyHunters used a single vishing call into the company's identity platform to breach Madison Square Garden
    active-threats
  16. 2026-06-21Amazon's One Medical confirms a legacy-storage breach; ShinyHunters' 8.8TB claim is unverified and its deadline expires today
    active-threats
  17. 2026-06-20Kodak confirms breach after ShinyHunters leak-site listing; June 18 deadline passed without publication
    active-threats
  18. 2026-06-13CVE-2026-48558, SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician session
    trending-vulnerabilities
  19. 2026-06-12CVE-2026-25089, Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)
    mentiontrending-vulnerabilities
  20. 2026-06-11ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration
    deep-dive
  21. 2026-05-29Carnival Corporation confirms 5.99 M-record ShinyHunters breach, passport + driver's-licence numbers exposed across four cruise brands
    active-threats
  22. 2026-05-27ShinyHunters Salesforce campaign; Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affected
    active-threats
  23. 2026-05-19Grafana Labs CoinbaseCartel breach; victim confirms source-code-only theft, no customer data, ransom rejected
    active-threats
  24. 2026-05-197-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records, same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic
    active-threats7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records, same campaign as Instructure, Vimeo, Wynn Resorts, Vercel
  25. 2026-05-16GTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrand
    active-threats
  26. 2026-05-09Inditex (Zara), ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromise
    active-threats
  27. 2026-05-08Instructure/Canvas extortion: 330 institutions across six countries; May 12 extortion deadline; 44 Dutch institutions confirmed
    active-threats
ATT&CK techniques (29 across 12 tactics)

29 techniques observed across 15 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ReconnaissancePhishing for Information: Spearphishing Voice
  • Initial AccessValid Accounts · Valid Accounts: Default Accounts · Valid Accounts: Cloud Accounts · Exploit Public-Facing Application · Supply Chain Compromise: Compromise Software Supply Chain · Trusted Relationship · Phishing · Phishing: Spearphishing Voice
  • PersistenceValid Accounts · Valid Accounts: Default Accounts · Valid Accounts: Cloud Accounts · Account Manipulation: Device Registration · Server Software Component: Web Shell · Modify Authentication Process · Modify Authentication Process: Multi-Factor Authentication
  • Privilege EscalationValid Accounts · Valid Accounts: Default Accounts · Valid Accounts: Cloud Accounts · Account Manipulation: Device Registration
  • StealthObfuscated Files or Information: Software Packing · Valid Accounts · Valid Accounts: Default Accounts · Valid Accounts: Cloud Accounts · Social Engineering: Impersonation
  • Defense ImpairmentSubvert Trust Controls: Code Signing · Modify Authentication Process · Modify Authentication Process: Multi-Factor Authentication
  • Credential AccessSteal Application Access Token · Unsecured Credentials: Private Keys · Modify Authentication Process · Modify Authentication Process: Multi-Factor Authentication · Adversary-in-the-Middle
  • Lateral MovementRemote Services: SSH
  • CollectionData from Information Repositories · Data from Information Repositories: Sharepoint · Data from Information Repositories: Code Repositories · Data from Cloud Storage · Adversary-in-the-Middle
  • Command and ControlRemote Access Tools · Protocol Tunneling
  • ExfiltrationExfiltration Over Web Service · Exfiltration Over Web Service: Exfiltration to Cloud Storage
  • ImpactDefacement: External Defacement

Reconnaissance TA0043

T1598.004Phishing for Information: Spearphishing Voice×1

Adversaries may use voice communications to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Spearphishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×3

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×4

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗

T1190Exploit Public-Facing Application×5

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-24/shinyhunters-fbi-peoplesoft-breach-claim · 2026-07-01/oracle-e-business-suite-cve-2026-46817-pre-auth-rce-in-the-p · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-05-19/grafana-labs-coinbasecartel-breach-victim-confirms-source-co · ATT&CK page ↗

T1199Trusted Relationship×2

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · ATT&CK page ↗

T1566Phishing×1

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice×6

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×3

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×4

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

T1556Modify Authentication Process×1

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×2

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×3

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×4

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

Stealth TA0005

T1027.002Obfuscated Files or Information: Software Packing×1

Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code.

Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

T1078Valid Accounts×3

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×4

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗

T1684.001Social Engineering: Impersonation×1

Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims.

Evidence: 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · ATT&CK page ↗

Defense Impairment TA0112

T1553.002Subvert Trust Controls: Code Signing×1

Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature.

Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

T1556Modify Authentication Process×1

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×2

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · ATT&CK page ↗

Credential Access TA0006

T1528Steal Application Access Token×3

Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.

Evidence: 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1552.004Unsecured Credentials: Private Keys×1

Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc.

Evidence: 2026-05-19/grafana-labs-coinbasecartel-breach-victim-confirms-source-co · ATT&CK page ↗

T1556Modify Authentication Process×1

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×2

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

Lateral Movement TA0008

T1021.004Remote Services: SSH×1

Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.

Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×3

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

T1213.002Data from Information Repositories: Sharepoint×2

Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint:

Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

T1213.003Data from Information Repositories: Code Repositories×1

Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.

Evidence: 2026-05-29/carnival-corporation-confirms-5-99-m-record-shinyhunters-bre · ATT&CK page ↗

T1530Data from Cloud Storage×4
T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

Command and Control TA0011

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

T1572Protocol Tunneling×1

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×4

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · 2026-05-19/grafana-labs-coinbasecartel-breach-victim-confirms-source-co · ATT&CK page ↗

T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Evidence: 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗

Impact TA0040

T1491.002Defacement: External Defacement×1

An adversary may deface systems external to an organization in an attempt to deliver messaging, intimidate, or otherwise mislead an organization or users. External Defacement may ultimately cause users to distrust the systems and to question/discredit the system’s integrity. Externally-facing websites are a common victim of defacement; often targeted by adversary and hacktivist groups in order to push a political message or spread propaganda. External Defacement may be used as a catalyst to trigger events, or as a response to actions taken by an organization or government. Similarly, website defacement may also be used as setup, or a precursor, for future attacks such as Drive-by Compromise.

Evidence: 2026-09-24/shinyhunters-fbi-peoplesoft-breach-claim · ATT&CK page ↗

Entries about ShinyHunters (23)

2026-09-24 · view entry permalink →

HIGHupdatedNATOB2

ShinyHunters claims a breach of the FBI's own recruitment infrastructure via an unconfirmed Oracle PeopleSoft zero-day; the FBI now confirms the compromise itself while still investigating scope

The extortion group ShinyHunters claims it breached the FBI's own recruitment infrastructure using a new, undisclosed remote-code-execution zero-day in Oracle PeopleSoft, often used by human resources and recruiters to store job applicants' personal information (TechCrunch, 2026-09-22). "The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure" (BleepingComputer, 2026-09-22). ShinyHunters claims it stole 2-3TB of data, names, agent statuses, emails, phone numbers, home addresses and in some cases spouses' information including Social Security numbers (Axios, 2026-09-22), spanning current and former FBI employees and job applicants, and that it compromised additional internal services including Criminal Justice, HR and Medlink systems along the way (BleepingComputer, 2026-09-22). The group defaced the FBI's careers site, apply.fbijobs.gov, with its Umbreon Pokémon logo and a message claiming the theft; the FBI took the site offline, and it now shows a maintenance page. The FBI's confirmed response is limited to a single statement: "The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," (FBI, quoted by BleepingComputer, 2026-09-22); the bureau has not confirmed a breach occurred, its scope, or the claimed PeopleSoft zero-day, and "BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data" (BleepingComputer, 2026-09-22).

404 Media first reported the claim after receiving a sample of roughly 5,000 alleged FBI personnel records; "the publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel" (BleepingComputer, relaying 404 Media, 2026-09-22), which supports that some genuine personnel data changed hands without confirming the exploitation mechanism or the full claimed volume. ShinyHunters' own account of the vulnerability is unusually specific but still entirely self-reported: "The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI," (ShinyHunters, quoted by BleepingComputer, 2026-09-22) and the group says it is now exploiting the same alleged flaw against other organizations, including Fortune 500 companies, after previously targeting the education sector with a PeopleSoft campaign (BleepingComputer, 2026-09-22). ShinyHunters frames the FBI intrusion as retaliation for a May 2026 FBI/IC3 flash report naming the group, demanding a correction within one week rather than a ransom and claiming the demand is not financially motivated (BleepingComputer, 2026-09-22). The same week, ShinyHunters separately defaced the ransomware group Clop's own Tor leak site over an unrelated dispute, using it to extort Clop directly (BleepingComputer, 2026-09-19); a parallel campaign against a different victim that this entry does not otherwise cover.

The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure.

BleepingComputer 2026-09-22

The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,

FBI, quoted by BleepingComputer

BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data.

BleepingComputer 2026-09-22

The publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel.

BleepingComputer, relaying 404 Media's own verification

ShinyHunters told Axios in an email that the stolen data includes names, FBI agent statuses, emails, phone numbers, home addresses and "sometimes even spouse information," including their Social Security numbers.

Axios 2026-09-22

ShinyHunters has confirmed to BleepingComputer that they used this WAF bypass against FBI Jobs, but continue to claim that they also exploited "NEW unknown vulnerability in the same PSEMHUB component."

BleepingComputer 2026-09-22

The FBI hasn't confirmed the type or amount of data compromised or attributed the breach to ShinyHunters directly. The agency said it is "actively and aggressively investigating" the incident, the root cause and its alleged impact to FBI employees' personally identifiable data in a statement Wednesday.

Limited samples of the stolen data contain FBI agents' personal contact information, details on family members, office and duty assignments and, in some cases, information on agency personnel specialties, multiple sources said.

CyberScoop 2026-09-22

In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.

Krebs on Security 2026-09-28

Since the very beginning we had made our decision that we would never publish this data. We have never intended to nor have we ever planned to

ShinyHunters, quoted by Nextgov/FCW

Reuters reported Friday that records circulated by the hackers included psychiatric and medical evaluations. The BBC also reported seeing blood and urine test results.

Nextgov/FCW 2026-09-28
Updaterun 2026-09-27T0404Z-intelevidencesourcesbody

Part of this entry's central open question, whether ShinyHunters' claimed FBI-specific zero-day was real, is now partially resolved. Mandiant/GTIG's report on a separate, wider mass-exploitation wave against the already-known CVE-2026-35273 documents a URL-encoded WAF-bypass technique (requesting /%50SEMHUB/ in place of /PSEMHUB/), and BleepingComputer reports: "ShinyHunters has confirmed to BleepingComputer that they used this WAF bypass against FBI Jobs, but continue to claim that they also exploited "NEW unknown vulnerability in the same PSEMHUB component."" (BleepingComputer, 2026-09-26). At least part of the FBI Jobs intrusion therefore used a known technique against a known CVE rather than the wholly undisclosed zero-day this entry originally reported, though ShinyHunters still claims an additional, still-unconfirmed vulnerability was also involved; the FBI has not updated its own statement and no party has confirmed or denied either technical claim.

Defender takeaway (updated): any organization running Oracle PeopleSoft, not only recruitment or applicant-facing instances, should treat the WAF-bypass technique as active and in use against government targets specifically; a WAF rule blocking the literal /PSEMHUB/ path is not sufficient, since ShinyHunters is confirmed using the URL-encoded /%50SEMHUB/ variant, and Mandiant warns further encoded or mixed-case variants may follow. Patch to a supported PeopleTools release or remove PSEMHUB rather than relying on WAF string-matching alone.

Updaterun 2026-09-29T0405Z-inteltitleheadlinesummaryentitiesclassificationsourcesevidencesourcing_notebody

The FBI has now issued its own press release confirming the fbijobs.gov compromise and "alleged impact" to employee personally identifiable information, superseding its prior "aware of claims ... investigating" holding statement: "The FBI hasn't confirmed the type or amount of data compromised or attributed the breach to ShinyHunters directly. The agency said it is 'actively and aggressively investigating' the incident, the root cause and its alleged impact to FBI employees' personally identifiable data in a statement Wednesday" (CyberScoop, 2026-09-28). Nextgov/FCW reports that Reuters found the circulated records included psychiatric and medical evaluations, and that the BBC separately reported seeing blood and urine test results: "Reuters reported Friday that records circulated by the hackers included psychiatric and medical evaluations. The BBC also reported seeing blood and urine test results" (Nextgov/FCW, 2026-09-28). The group separately provided Nextgov/FCW a roughly 5,000-entry sample of names, home addresses, phone numbers and relatives' information, and Nextgov/FCW's own earlier reporting found the exposed data identifies employees working intelligence matters involving Russia, China, Hezbollah and cartels, plus personnel in the Bureau's Remote Operations Unit, which develops tools to target computers and networks (Nextgov/FCW, 2026-09-24). CyberScoop separately reports: "Limited samples of the stolen data contain FBI agents' personal contact information, details on family members, office and duty assignments and, in some cases, information on agency personnel specialties, multiple sources said" (CyberScoop, 2026-09-28). Security researchers Jon DiMaggio (Arkem Cyber) and Cynthia Kaiser (a former FBI official, now at Halcyon) warn the exposure creates counterintelligence and physical-safety risk for agents on sensitive cases, and that data already shared with journalists as proof samples is irretrievably disseminated regardless of any later takedown. ShinyHunters told Nextgov/FCW it will not publish the stolen data: "Since the very beginning we had made our decision that we would never publish this data. We have never intended to nor have we ever planned to" (Nextgov/FCW, 2026-09-28), and states the intrusion's motive is coercive rather than financial: it is demanding the FBI retract or amend a May 2026 public advisory (PSA260515) describing the group's operations and tactics, disputes any affiliation with "The Com" cybercrime ecosystem, and denies using sextortion-style threats.

Dutch police separately confirmed, via a statement on X on 2026-09-28, the arrest of a 24-year-old suspect connected to the ShinyHunters investigation; three sources identify him to Krebs on Security as Pepijn van der Stap ("Umbreon"), a previously convicted cybercriminal who volunteered at the Dutch Institute for Vulnerability Disclosure and worked as a software engineer at a Dutch cybersecurity firm. Dutch police are separately asking the public to help identify a voice in a recorded February 2026 call in which a ShinyHunters member social-engineered access into Odido, the country's largest mobile carrier; Krebs states it remains unclear whether police have matched that voice to a confirmed identity, so this entry does not treat the Odido case as resolved or connected to the September arrest. Krebs reports: "In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p" (Krebs on Security, 2026-09-28). Multiple sources cited by Krebs describe a collective calling itself ScatteredLapsussHunters, led by a Jordan-based teenage cybercriminal known as "Rey," as having taken effective control of ShinyHunters' operations and driven its 2026 pivot toward high-risk, non-financially-motivated targets including the FBI and Cl0p; the FBI defacement reused van der Stap's old "Umbreon" artwork, which sources say may have been an attempt to pin the FBI intrusion on the arrested Dutch hacker rather than the group's current operators. CyberScoop separately quotes DiMaggio's independent assessment that "ShinyHunters" today operates as a criminal brand used by a fluid network rather than a single fixed group, corroborating the brand-fragmentation picture without itself confirming the ScatteredLapsussHunters/Rey narrative.

Defender takeaway (updated): treat "ShinyHunters" as a brand a fluid, currently fragmenting network of operators uses, not a fixed group with stable objectives; its current operators have demonstrated willingness to target law-enforcement and national-security-adjacent personnel data specifically, and to pursue coercive, non-financial demands rather than the financially motivated pattern this constituency may have hunted for previously. For a national or cantonal police service or defense IT estate, the transferable lesson is that staff-directory and personnel-system data (contact details, duty assignments, family information) carries a counterintelligence and physical-safety value to this actor class independent of any ransom potential, and should be protected and monitored accordingly.

incident24 Sep 04:50Zmulti-sourceOpen finding →

2026-06-11 · view entry permalink →

CRITICALCVE-2026-35273exploitedupdatedNATOB1

ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration

ShinyHunters confirmed to BleepingComputer on 10 June 2026 that it had compromised Oracle PeopleSoft servers across approximately 300 instances at more than 100 organisations, with a heavy concentration in higher education (BleepingComputer, 2026-06-10). The University of Nottingham confirmed the same day that student and alumni data had been accessed in a security incident affecting its student-record system, opened a dedicated support line, and notified Action Fraud and the ICO (University of Nottingham, 2026-06-10). TechCrunch independently corroborated the scale of the campaign and the education-sector skew (TechCrunch, 2026-06-10).

Access and exploitation. ShinyHunters describes initial access as a "gadget chain" combining legacy PeopleSoft vulnerabilities with claimed zero-days; the actor stresses that exploitation is configuration-dependent and not universal across all internet-reachable instances. Oracle has not published a CVE for the specific flaws in this campaign and did not respond to press inquiries, so the precise initial-access vector remains attacker-asserted rather than vendor-confirmed, treat the "zero-day" framing with appropriate caution. The relevant entry surface is the externally reachable PeopleSoft web and application tier (PIA, Integration Broker, and REST/SAML/OAuth endpoints), mapped to T1190 Exploit Public-Facing Application.

Post-access lateral movement. The better-evidenced (and more directly defender-actionable) phase is what follows initial access. The actor's tooling attempts SSH connections against common PeopleSoft/Oracle operating-system service accounts (psoft, oracle, linuxadm) using password and key-based fallback, then runs a shell script that performs bulk data retrieval and drops ransom notes into PeopleSoft web/application server directories (BleepingComputer, 2026-06-10). This maps to T1078.001 Valid Accounts: Default Accounts, T1021.004 Remote Services: SSH, and T1213 Data from Information Repositories, culminating in T1567 Exfiltration Over Web Service. Exfiltrated data categories stated by the actor include student and applicant records, financial-aid data, immigration status, health records, and contact details, the full sensitive payload of a campus-management deployment.

Detection and hunting concepts (no IOCs). Watch for SSH authentication attempts to PeopleSoft hosts using the psoft/oracle/linuxadm account names from external or unexpected source ranges; correlate against successful logons followed by interactive shell activity. On the application tier, alert on anomalous bulk-query volumes or out-of-hours mass record retrieval in PeopleTools security-audit logs, and on egress anomalies consistent with bulk data transfer to non-standard destinations. Treat the appearance of unexpected ransom-note text files in web/app server document roots as a high-confidence lateral-movement indicator and review authorized_keys and /etc/hosts for unauthorised additions.

Hardening / mitigation. Rename or disable the default psoft/oracle/linuxadm OS service accounts and enforce SSH key-only authentication; restrict PeopleSoft administrative interfaces to jump-host access and remove direct internet exposure of the management tier; enable PeopleTools security-audit logging if not already on; and apply any outstanding Oracle Critical Patch Update advisories for PeopleSoft, recognising that the campaign's specific CVEs are undisclosed so defence-in-depth around authentication and exposure is the dependable control. Public-sector and university SOCs running PeopleSoft Campus Solutions or HCM should audit external reachability of the web/app tier as the first action.

Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component.

Google/Mandiant GTIG

Google's Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish its advisory until June 10, so the bug was a zero-day the entire time.

The Hacker News

The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component

Mandiant GTIG

CVE-2026-35273 is a critical remote code execution vulnerability (CVSS 9.8) in Oracle PeopleTools versions 8.61 and 8.62 that exploits a server-side request forgery flaw in the Environment Management component

Rapid7

This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure.

Across compromised instances, a quarter of the threat actor's commands executed as root or NT Authority\\SYSTEM, granting full control of the operating system.

Mandiant GTIG

Google says the new wave of attacks has deployed web shells on dozens of systems worldwide within higher education, technology, IT services, healthcare, agriculture, transportation, and government organizations.

BleepingComputer
Updaterun 2026-06-12-5ab9a319actionscvesentitiesevidenceimmediate_actionprioritysourcestagsbody

The initial-access vector that was attacker-asserted yesterday is now vendor-confirmed: Oracle assigned CVE-2026-35273 (CVSS 9.8), an unauthenticated RCE in the PeopleTools Environment Management Hub (PSEMHUB, versions 8.61/8.62), and published an out-of-band Security Alert with fixes (Oracle, 2026-06-10; SecurityWeek, 2026-06-11).

Mandiant GTIG formally attributes the campaign to UNC6240 (ShinyHunters), dating exploitation 27 May – 9 June (a zero-day for the full window) and details the post-exploitation chain: customised MeshCentral remote-management agents masquerading as Microsoft Azure components for persistence and C2, and a per-victim _fanout.sh lateral-movement script spraying SSH credentials against internal hosts harvested from /etc/hosts (T1190, T1021.004). Mandiant notified more than 100 organisations with exposed PSEMHUB endpoints; 68 % are higher-education institutions (Mandiant GTIG, 2026-06-11).

The University of Nottingham (confirmed as a victim yesterday) now quantifies the damage: roughly 40 GB exfiltrated covering ~455,000 individuals across its UK, Malaysia and China campuses, including names, contact details, ethnicity, disability, passport and tuition-payment data; the ICO says it is assessing the report (BleepingComputer, 2026-06-11; The Record, 2026-06-11; University of Nottingham, 2026-06-10). Action: see the § 0 callout, patch out-of-band and compromise-assess; yesterday's hardening guidance (default SSH service accounts, PSEMHUB exposure) stands.

Updaterun 2026-06-13-40b26572actionscvesevidenceregionssourcestagsbody

Mandiant and Google GTIG formally attribute the PeopleSoft Environment Management Hub exploitation campaign to UNC6240 (ShinyHunters) and confirm the activity ran from 27 May to 9 June 2026, predating Oracle's 10 June out-of-band advisory, establishing CVE-2026-35273 (CVSS 9.8) as a zero-day at time of exploitation (Mandiant/GTIG, 2026-06-11). The unauthenticated SSRF→RCE is reached via the /PSEMHUB/hub and /PSIGW/HttpListeningConnector endpoints in PeopleTools 8.61/8.62.

GTIG notified over 100 organisations whose endpoints correlated with exploitation; 68% are higher-education institutions. Post-exploitation, the actor deployed MeshCentral remote-management agents disguised as Azure binaries, used SSH fan-out scripts with PeopleSoft admin credentials for lateral movement, and exfiltrated to the ShinyHunters leak site (Rapid7, 2026-06-12). The University of Nottingham confirmed 454,600 student and alumni records were taken, including passport numbers (University of Nottingham; BleepingComputer, 2026-06-11). CISA added the CVE to KEV on 12 June. Swiss/EU universities running Campus Solutions should treat this as P1 (.

Updaterun 2026-06-16-38d638e1actionssourcestagsbody

ShinyHunters listed the Council of Europe (the 46-member Strasbourg human-rights body, of which Switzerland is a member) claiming 297 GB across ~429,000 files taken via the Oracle PeopleSoft Environment Management Hub zero-day CVE-2026-35273, and set a 16 June leak deadline (SecurityWeek, 2026-06-15). This is the first European intergovernmental institution named in the 100+-organisation PeopleSoft campaign previously covered as an education-sector wave.

The claimed dataset spans payroll for 10,000+ current and former staff (2011–2026), 14,000+ CVs, and HR records with names, dates of birth, addresses, bank-account, tax/social-security and medical data. The Council of Europe confirmed it "is currently investigating the matter and assessing the situation" and has not confirmed exfiltration (The Register, 2026-06-15; BleepingComputer, 2026-06-15). The vector, unauthenticated HTTP to the /PSEMHUB/hub servlet (T1190), is unchanged; treat any externally-reachable PeopleSoft Environment Management Hub as compromised pending forensic review and block perimeter access to /PSEMHUB/*. Confidence on the victim claim is MEDIUM pending Council of Europe confirmation (extortion-site claim).

Updaterun 2026-09-27T0404Z-intelimmediate_actionsectorstechniquesaffected_productsclassificationactionssourcesevidencebody

Mandiant and GTIG report that UNC6240 (ShinyHunters) has resumed mass exploitation of CVE-2026-35273, adapting to the defensive guidance this campaign's own earlier coverage carried. The actor now bypasses WAF rules that block the literal /PSEMHUB/ path by requesting the URL-encoded /%50SEMHUB/ instead: many WAFs and reverse proxies match the request path before decoding it, while the PeopleSoft application server decodes and routes the request normally. "This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure" (Mandiant/GTIG, 2026-09-25). Mandiant warns the actor may rotate to other percent-encoded, mixed-case or otherwise non-normalized path variants, so defenders should block on the normalized path rather than the literal string.

Before exploiting a target, the actor sends five to fifteen POST requests carrying a serialized Java object to quietly confirm exploitability without writing files or disrupting the service. Two complementary single-line JSP web shells are then dropped into the PSEMHUB.war directory: x.jsp executes hex-encoded commands cross-platform, and u.jsp/u2.jsp upload larger files in 150 KB Base64-encoded chunks, bypassing PeopleSoft's own file-size limits; a fileless variant returns command output directly in the HTTP response with nothing written to disk, defeating file-creation-based detection. On compromised Windows hosts, the actor uploads a trojanized installer, Ple64.exe, masquerading as a signed Light Alloy media-player installer and signed with a valid Extended Validation certificate Mandiant has asked the issuing certificate authority to revoke; it loads a VMProtect-3-packed multi-stage chain culminating in the SIDEEYE C++ backdoor, which steals browser and desktop credentials, manages processes and files, and provides an interactive reverse shell and reverse proxy over raw TCP. The actor also deploys the open-source Neo-reGeorg tunneling toolkit to route SOCKS5 proxy traffic over ordinary HTTP/S for internal lateral movement, and uses the legitimate MeshAgent/MeshCentral remote-management platform to maintain access on Linux hosts. "Across compromised instances, a quarter of the threat actor's commands executed as root or NT Authority\SYSTEM, granting full control of the operating system" (Mandiant/GTIG, 2026-09-25).

Targeting has expanded well beyond the original higher-education skew: "Google says the new wave of attacks has deployed web shells on dozens of systems worldwide within higher education, technology, IT services, healthcare, agriculture, transportation, and government organizations" (BleepingComputer, 2026-09-26), and Mandiant's report names government among the sectors this wave has hit alongside the Council of Europe's earlier confirmed intergovernmental role. Mandiant's remediation guidance is unchanged in substance but sharper: apply the Oracle Security Alert and stay on a supported PeopleTools release rather than relying on a WAF at all; disable EMHub or remove PSEMHUB if not needed, since neither is required for standard PeopleSoft Internet Architecture user sessions; search WebLogic access logs for requests to /PSEMHUB/ and its encoded variants and for POST requests to /hub with external-source bodies; and, on any host where a web shell is found, treat it as compromised, preserve evidence, and rotate every credential reachable from the PeopleSoft tier, prioritising hosts where WebLogic runs as root or SYSTEM.

This wave also clarifies part of a separately-tracked claim: ShinyHunters told BleepingComputer it used this same WAF-bypass technique against the FBI's own recruitment site, alongside a further, still-unconfirmed vulnerability it says it also exploited there; see the FBI PeopleSoft entry for that update.

threat11 Jun 05:00Zmulti-sourceOpen finding →

2026-08-28 · view entry permalink →

NOTABLENATOB2

Troy Hunt: a 24.9M-address ShinyHunters/Carhartt breach-claim collapses to 12.9M real records once TPC-DS synthetic benchmark data and several duplicate/test-account patterns are filtered out, a reusable methodology for verifying inflated breach-claim record counts

Following ShinyHunters' 2026-08-13 claim to have stolen 50GB+ of Carhartt customer data, Troy Hunt's initial Have I Been Pwned processing run found 24,876,077 unique email addresses in the dump. Using an AI chat assistant he calls "PwnedClaw" to help work through the corpus, while directing every step and validating each finding against the raw data himself; Hunt ran domain-frequency analysis, TLD pattern checks, and birth-country and birth-year distribution analysis, and found the bulk of the corpus was TPC-DS retail-analytics-benchmark synthetic test data that had been sitting in the same Databricks schema ShinyHunters exfiltrated, which the actor, and, per Hunt, "every aggregator after them", failed to distinguish from real customer records before publishing.

The diagnostic signals were all independently conclusive. PwnedClaw's frequency analysis found 97.6% of domains in the corpus appeared exactly once: "97.6% of domains appear exactly once, that's not a long tail, that's a signature. Real breach data from a retail company would have thousands of addresses on corporate domains, hundreds on ISP domains, a natural power law. Instead you have 10.1M singleton domains. That's pure TPC-DS generation" (PwnedClaw, quoted by Troy Hunt, 2026-08-25). An initial 32% of addresses used syntactically plausible names on gibberish .edu/.org domains, and the same pattern was found to extend across .com and every TLD once Hunt pushed further: 54.8% of addresses (13.6M) sat on domains appearing 100+ times (real), against 45.2% (11.25M) on domains appearing under 100 times, the synthetic share, not the initially-estimated 32%. Birth-country data was perfectly uniform across all 211 ISO country codes (roughly 380–420 records per country, with the US tied with Canada and dwarfed by e.g. Antigua and Barbuda and Lesotho) rather than concentrated in Carhartt's actual US/European customer base. Birth-year distribution was mathematically flat from 1924–1992: "birth year stats are conclusive. The distribution runs 1924-1992 and is perfectly flat, roughly 1,050-1,194 per year, every single year without exception. That's not population data, that's a random number generator with a fixed range" (PwnedClaw, quoted by Troy Hunt, 2026-08-25), no weighting toward a plausible customer-age curve.

Corroborating evidence the real customer data is present and genuinely breached: internal @carhartt.com employee addresses (15,057 of them), 32-character hex-prefixed internal aliases and the internal carharttdonotship.com domain (none of which an external actor could fabricate or scrape) plus a 70% hit rate against HIBP's existing freemail dataset and purchase-tagged sub-addresses (+carhartt, +paypal, and similar). PwnedClaw's synthesis: "the conclusion is pretty solid: this is a real Carhartt Databricks breach, but the TPC-DS benchmark data was co-located in the same schema and ShinyHunters (and every aggregator after them) grabbed it all without knowing what they were looking at" (PwnedClaw, quoted by Troy Hunt, 2026-08-25).

Excluding the identified TPC-DS synthetic chunk files (600 plus a further 1,200) dropped the count from 24.9M to 13,306,258, a 47% reduction, and still not the final figure. Hunt's own further manual review, again assisted by PwnedClaw, found and removed several more inflation sources: 5,736 Microsoft-365 domain-alias triplicates (the same mailbox counted three times across carhartt.com, carhartt.onmicrosoft.com and carhartt.mail.onmicrosoft.com); 285,808 deactivate--prefixed soft-delete duplicates (with 3,174 renamed back to their active form where no duplicate existed); and 48,787 wctest.com plus 32,514 carharttdonotship.com addresses, both internal performance-test domains identified by a shared perftest alias pattern rather than real customers. The final published figure (which Hunt's own tweet states directly) is 12,933,413 unique addresses: "New breach: Carhartt was the target of a ShinyHunters extortion campaign earlier this month. Data allegedly obtained from the company was later published, including 12.9M unique email addresses. 83% were already in @haveibeenpwned" (Troy Hunt, 2026-08-25), a little over half of ShinyHunters' implied headline scope.

The methodology is region-agnostic: Carhartt itself is a US retailer, but the finding is a reusable verification methodology for any SOC or CTI team triaging leak-site record-count claims, not a victim-specific disclosure. It is also a case study in AI-assisted analysis discipline: an AI assistant's confident, well-phrased analytical output is not automatically fact, and PwnedClaw's own intermediate 13.3M figure was itself superseded by further manual review, the analyst directing it still owns validating every claim and every number against the underlying data before publishing.

97.6% of domains appear exactly once, that's not a long tail, that's a signature. Real breach data from a retail company would have thousands of addresses on corporate domains, hundreds on ISP domains, a natural power law. Instead you have 10.1M singleton domains. That's pure TPC-DS generation.

Birth year stats are conclusive. The distribution runs 1924-1992 and is perfectly flat, roughly 1,050-1,194 per year, every single year without exception. That's not population data, that's a random number generator with a fixed range.

The conclusion is pretty solid: this is a real Carhartt Databricks breach, but the TPC-DS benchmark data was co-located in the same schema and ShinyHunters (and every aggregator after them) grabbed it all without knowing what they were looking at.

PwnedClaw, quoted by Troy Hunt (Have I Been Pwned)

New breach: Carhartt was the target of a ShinyHunters extortion campaign earlier this month. Data allegedly obtained from the company was later published, including 12.9M unique email addresses. 83% were already in @haveibeenpwned.

Troy Hunt (Have I Been Pwned) 2026-08-25
research28 Aug 06:50Zsingle-sourceOpen finding →

Earlier coverage (20)

2026-07-18NOTABLEupdatedNATOA3Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ recordsAbbott Laboratories confirmed (2026-07-16) unauthorized access to a limited number of internal systems in its Cancer Diagnostics business (the acquired Exact Sciences unit) only. Separately, the ShinyHunters extortion group claims the intrusion began with a vishing call that compromised a Microsoft Entra ID single-sign-on account, then used it to pull 30M+ records from Entra, ServiceNow, SharePoint, Databricks and Coupa; a claim Abbott has neither confirmed nor attributed. The confirmed incident plus the same vishing-to-cloud-SSO tradecraft this actor uses against SaaS-integrated enterprises makes it relevant to healthcare and any SharePoint/Entra-dependent estate.2026-07-19NOTABLEupdatedNATOA2Ernst & Young discloses a breach of a third-party IT support-ticket platform used by its tax practice, exposing client tax and financial documentsErnst & Young LLP filed breach notifications (2026-07-15) after detecting that an unauthorized party accessed a third-party IT service-management (ITSM) support-ticket platform used by its tax practice between 28 March and 12 April 2026 and downloaded documents belonging to multiple tax clients. Support tickets on the platform carried attached client tax and financial information; EY has not disclosed the access vector, the platform, or how many are affected. The transferable lesson for any organization (public-sector included) that outsources IT helpdesk/ticketing: sensitive attachments accumulate inside support-ticket systems that data-classification and DLP programs routinely overlook.2026-07-14NOTABLENATOB2Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers, none exploiting a Salesforce vulnerabilityMicrosoft Threat Intelligence documented a year (mid-2025 to mid-2026) of campaigns using ShinyHunters-associated tradecraft (registry alias UNC6240) against Salesforce-integrated SaaS environments via three intrusion paths: vishing-driven malicious-OAuth-consent (a fake Data Loader app), SaaS supply-chain OAuth-secret reuse (Salesloft Drift, Gainsight, and Storm-3138's June 2026 Klue compromise), and guest-access Aura abuse. None exploited a Salesforce flaw, all abuse trusted OAuth relationships, so sign-in-anomaly detection gives limited visibility.2026-07-10HIGHNATOB2'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltrationReliaQuest documented a previously unreported data-extortion cluster it calls Helix, assessed as a likely continuation of the BlackFile (UNC6671) and ShinyHunters ecosystems on shared registrar and hosting infrastructure. Operators phone a target impersonating their named manager (spoofed caller-ID), walk them through an Entra ID device-code sign-in that captures a session token without a password and sidesteps Conditional Access, register a new Authenticator within minutes for persistence, then run automated SharePoint enumeration and bulk exfiltration. SharePoint + Entra ID is the default identity/collaboration stack across Swiss and EU public-sector tenants, so the playbook is directly reachable; disabling the device-code flow is the single highest-impact control.2026-07-10NOTABLENATOA2ShinyHunters' Odido (NL telecom) breach: Dutch police voice analysis points to Dutch-national involvement; same vishing-into-spoofed-portal playbook, now against an EU telcoDutch National Police announced on 9 July 2026 that its investigation into the February 2026 ShinyHunters breach of telecom operator Odido (and its Ben brand) found strong indications of Dutch-national involvement, based on forensic voice analysis of a call recorded during the intrusion. The intrusion used the ShinyHunters playbook already tracked in this store: a vishing call impersonating IT staff persuaded a customer-service employee to authenticate into a spoofed corporate portal, harvesting credentials used to bulk-export 6.2M+ customer records before the account was blocked within an hour. The new signal is the EU-telco victim, the law-enforcement attribution, and two open Dutch DPA investigations; the underlying TTP is the ShinyHunters playbook already tracked in this store.2026-07-03HIGHMedtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach, 2.5 months after containmentMedtronic is notifying ~9 million people of a ShinyHunters-claimed April breach of corporate IT systems (names, DOB, SSNs, health data), 2.5 months after containment; it says medical devices were unaffected and segregated from the compromised networks (BleepingComputer, 2026-07-02).2026-07-01NOTABLEexploitedOracle E-Business Suite CVE-2026-46817: pre-auth RCE in the Payments File Transmission servlet, first in-the-wild exploitationWhat it is. CVE-2026-46817 (CVSS 9.8) is an unauthenticated remote-code-execution flaw in the File Transmission component of Oracle Payments, part of Oracle E-Business Suite, affecting EBS 12.2.3 through 12.2.15.2026-06-28HIGHexploitedupdatedNAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pauseNAIC (the standard-setting body for all 50 US state insurance regulators) confirms a breach via an Oracle PeopleSoft zero-day; ShinyHunters published ~3.1 TB of insurance regulatory and credit-rating-agency data, and rating-agency feeds paused, forcing NAIC to suspend assigning investment-risk designations. Part of a 100+ org PeopleSoft zero-day campaign; any organisation running Oracle PeopleSoft should verify patch status against the campaign (NAIC, 2026-06-26).2026-06-27NOTABLEUK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach, 160 universities, ShinyHunters extortion, ransom paidThe UK Cyber Monitoring Centre (CMC) published a post-incident sector review on 2026-06-25 of the April 2026 ShinyHunters (UNC6240) breach of Instructure's Canvas learning-management platform, which affected roughly 160 UK higher-education institutions (Computer Weekly, 2026-06-25).2026-06-26HIGHShinyHunters used a single vishing call into the company's identity platform to breach Madison Square GardenShinyHunters breached Madison Square Garden through a single vishing call into the company's identity platform; 404 Media's review of the stolen data confirms a low-level employee was talked into letting the operators into MSG's systems, the same vishing → identity-platform (Entra/Okta) → MFA-enrollment kill chain that works equally well against EU public-sector tenants (404 Media, 2026-06-24).2026-06-21NOTABLEAmazon's One Medical confirms a legacy-storage breach; ShinyHunters' 8.8TB claim is unverified and its deadline expires todayOne Medical (Amazon) confirmed on 2026-06-13 that an unauthorised party accessed a legacy third-party file-storage system retaining archived records for One Medical Seniors (formerly Iora Health), during a 2026-06-08 to 2026-06-11 window, affecting demographic and clinical records for patients at nine clinics …2026-06-20NOTABLEKodak confirms breach after ShinyHunters leak-site listing; June 18 deadline passed without publicationEastman Kodak acknowledged on 17 June 2026 that "an unauthorized third party illegally gained access to a limited amount of company data," after ShinyHunters listed it on their dark-web leak site on 15 June claiming 2.2 million PII records and set an 18 June contact deadline (SecurityWeek, 2026-06-18 …2026-06-13HIGHCVE-2026-48558, SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician sessionSimpleHelp RMM ships an unauthenticated OIDC auth-bypass (CVE-2026-48558). A forged unsigned OIDC token yields a full technician session and bypasses IdP MFA, a clean initial-access vector into every downstream MSP-managed estate (Horizon3.ai, 2026-06-12).2026-05-27HIGHupdatedShinyHunters Salesforce campaign; Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affectedShinyHunters Salesforce extortion, two fresh victim confirmations. Charter Communications (Spectrum) confirmed a breach but disputes that sensitive PI or CPNI was taken (BleepingComputer, 2026-05-26), while 7-Eleven confirmed a breach affecting roughly 185,000 individuals; CyberInsider reports Social Security and driver's-licence numbers in the exposed set (CyberInsider, 2026-05-26); both trace to the vishing → Entra → Salesforce-Aura pattern.2026-05-29HIGHCarnival Corporation confirms 5.99 M-record ShinyHunters breach, passport + driver's-licence numbers exposed across four cruise brandsCarnival Corporation files substitute notices confirming a breach affecting 5,995,277 individuals (Maine AG filing; driver's-licence + passport numbers exposed across Princess / Holland America / Cunard / Costa per The Record). Maine AG records the breach occurring 2026-04-10 and discovered 2026-04-14 (single-employee-account social engineering); ShinyHunters claimed and ultimately published when ransom was refused.2026-05-19HIGHupdated7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records, same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records (SecurityWeek, 2026-05-18). Part of the broader ShinyHunters Salesforce-targeting campaign with co-victims Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic, phishing / OAuth / misconfiguration, not Salesforce-product vulnerabilities.2026-05-19NOTABLEGrafana Labs CoinbaseCartel breach; victim confirms source-code-only theft, no customer data, ransom rejectedUPDATE (originally covered 2026-W21): Grafana Labs issued an official 2026-05-18 confirmation of the GitHub Pwn-Request breach previously reported in the 2026-W21 weekly summary (SecurityWeek, 2026-05-18; BleepingComputer, 2026-05-18; The Register, 2026-05-18).2026-05-16HIGHGTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrandGTIG analyses UNC6671 "BlackFile" vishing-driven AiTM extortion: real-time helpdesk impersonation → attacker-registered lookalike SSO portals → MFA token capture and rogue MFA device registration → programmatic SharePoint exfiltration of 1M+ files per victim via Python requests spoofing the Microsoft Office ClientAppId; DLS shutdown signals probable rebrand (Google Threat Intelligence Group, 2026-05-15).2026-05-08HIGHupdatedInstructure/Canvas extortion: 330 institutions across six countries; May 12 extortion deadline; 44 Dutch institutions confirmed(First covered 2026-05-06.) The Instructure/Canvas breach has expanded significantly in scope.2026-05-09NOTABLEInditex (Zara), ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromiseHave I Been Pwned confirmed on 2026-05-08 that 197,400 unique email addresses from Inditex (Zara's parent, headquartered in A Coruña, Spain) were exposed following a breach of a former third-party analytics provider.

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats19
  • Vulns4
  • Deep dive2
  • Research2

Source distribution

  • bleepingcomputer.com22 (18%)
  • securityweek.com6 (5%)
  • theregister.com6 (5%)
  • attack.mitre.org5 (4%)
  • securityaffairs.com5 (4%)
  • msrc.microsoft.com4 (3%)
  • cloud.google.com3 (2%)
  • cyberinsider.com3 (2%)
  • other66 (55%)
All cited sources (120)