ShinyHunters
actor · actor:shinyhunters single-source
Financially motivated data-theft and extortion group (also tracked as UNC6240) behind the 2026 Salesforce/SaaS victim cluster (Instructure, Vimeo, 7-Eleven, Carnival, Inditex/Zara, Medtronic and others) and the Oracle PeopleSoft data-theft campaign.
Aliases: UNC6240
Coverage
27
23 about it · 4 mentions · first 2026-05-06 → last 2026-09-27
Latest activity
2026-09-29
The FBI confirms ShinyHunters compromised its jobs portal; a Dutch arrest exposes an internal power struggle…
Peak priority
critical
1 critical · 11 high · 11 notable
Targets
public-sector
sectors: public-sector, technology, healthcare · regions: europe, us, uk
Sources cited
120
55 hosts
2026-05-0827 appearances2026-09-27
Action items (12)
Do-now tasks recorded on the entries about ShinyHunters, newest first. Check the date before acting on an older one.
- Watch Oracle's own security-alert channel for an emergency PeopleSoft advisory in the coming days; any organization running an internet-facing PeopleSoft component, especially a recruitment or HR/jobs-portal instance matching the FBI's own claimed entry point, should treat unexplained PeopleSoft process activity or unusual outbound connections as a priority hunt lead until Oracle confirms or denies the claim.2026-09-24The FBI confirms ShinyHunters compromised its jobs…
- Immediate action: UNC6240 (ShinyHunters) is again mass-exploiting CVE-2026-35273 against organisations that patched their WAF but not PeopleSoft itself, using a URL-encoded path (2026-06-11CVE-2026-35273
/%50SEMHUB/) that many WAFs match before decoding. Apply Oracle's Security Alert or disable/remove PSEMHUB; where a WAF is the only control, reconfigure it to block on the normalized path, not the literal string, and search WebLogic access logs for/PSEMHUB/and any encoded or mixed-case variant (Mandiant/GTIG, 2026-09-25). - Patch every Oracle PeopleSoft instance to a supported PeopleTools release or disable/remove PSEMHUB now (CVE-2026-35273); a WAF rule alone no longer stops this. UNC6240 (ShinyHunters) bypasses literal-string2026-06-11CVE-2026-35273
/PSEMHUB/WAF blocks with the URL-encoded/%50SEMHUB/path, so a perimeter block that has not been reconfigured to match on the normalized path is not a control. Treat any instance that was internet-reachable and unpatched at any point since 27 May 2026 as compromised until proven clean, and rotate every credential reachable from the PeopleSoft tier. - Hunt for the post-exploitation toolkit on any PeopleSoft host. Search WebLogic access logs for2026-06-11CVE-2026-35273
/PSEMHUB/and its encoded/mixed-case variants; scanPSEMHUB.war/PORTAL.warfor unexpected.jsp/.jspx/.exefiles (includingPle64.exe); check for MeshAgent/MeshCentral agents and SSH credential-spraying against hosts in/etc/hosts; and review for ransom-note markers in PeopleSoft directories. - Audit Salesforce connected apps for unrecognized or over-privileged OAuth grants, specifically apps posing as legitimate integration tooling (e.g. a Data Loader lookalike) and any connected app inactive for 90+ days, and revoke them; this is the trust relationship the campaign abuses, and it is invisible to sign-in-anomaly detection.2026-07-14Microsoft maps a year of Salesforce OAuth abuse…
7 older action items
- Block or tightly scope the Entra ID device-code authentication flow tenant-wide, ReliaQuest names this the single highest-impact control, because it neutralises the session-token capture regardless of how convincing the vishing pretext is.2026-07-10ReliaQuest: new 'Helix' extortion cluster…
- Alert on a new MFA-authenticator registration occurring within minutes of a device-code sign-in from a residential-proxy IP the account has never used, that co-occurrence is Helix's persistence artifact and is otherwise indistinguishable from normal user activity.2026-07-10ReliaQuest: new 'Helix' extortion cluster…
- Hunt SharePoint/Graph access logs for enumeration using contentclass:STS_Site and wildcard search queries at automation speed from a non-browser (python-requests) user-agent, followed by bulk downloads; the automated-collection stage is the most reliable fingerprint.2026-07-10ReliaQuest: new 'Helix' extortion cluster…
- Reinforce helpdesk/customer-service verification: require out-of-band callback confirmation before any staff member authenticates in response to an inbound call claiming to be internal IT; the control that would have stopped both the Odido and the earlier tracked ShinyHunters vishing intrusions.2026-07-10Dutch police tie ShinyHunters' Odido telecom breach…
- Alert on a single account performing a bulk export from a customer-contact or CRM repository shortly after an interactive sign-in from an unusual location; Odido's operators bulk-downloaded 6.2M records before the account was blocked within the hour.2026-07-10Dutch police tie ShinyHunters' Odido telecom breach…
- Confirm CVE-2026-35273 (Oracle PeopleSoft PeopleTools) is patched and PeopleSoft PeopleTools is off the public internet; the ShinyHunters campaign is still acquiring named victims (Nissan).2026-06-28CVE-2026-35273
- Patch SimpleHelp to 5.5.16 / 6.0 RC2, or disable OIDC, CVE-2026-48558 lets an unauthenticated attacker forge an OIDC token into a full Technician session and bypass IdP MFA; review access logs for no-signature token exchanges preceding successful Technician auth (.2026-06-13CVE-2026-48558
Defender insights
What each entry about ShinyHunters tells a defender to do, newest first.
Latest update
Detection
Latest update · triage
Latest update
Triage
Triage
7 earlier entries carry guidance too, listed under the story timeline below.
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
overlaps with
- Helixshared registrar and hosting-adjacent infrastructure per ReliaQuest
- ScatteredLapsussHuntersKrebs on Security (2026-09-28): sources say ShinyHunters' 2026 operations are now effectively directed by 'Rey' of ScatteredLapsussHunters (SLSH), which experts say is 'an amalgamation of three hacking groups, Scattered Spider, LAPSUS$ and ShinyHunters.'
attributed activity
- Brinks Home breach (July 2026)Claimed by ShinyHunters; the company has confirmed neither the attribution nor the claimed data volumes.
- Carnival Corporation breach
- Charter/Spectrum listing
- Ernst & Young third-party ITSM breachLeak-site self-claim only, ShinyHunters claimed responsibility to BleepingComputer, which could not verify it; EY has not confirmed the attribution
- Kodak breach
- Madison Square Garden breach
- NAIC PeopleSoft breach
- Odido (Netherlands telecom) ShinyHunters breach
- One Medical legacy-storage breach
- ShinyHunters claimed breach of the FBI via an Oracle PeopleSoft zero-dayShinyHunters claimed the intrusion directly to BleepingComputer, TechCrunch and 404 Media.
- ShinyHunters PeopleSoft campaign
Story timeline
Every entry that names ShinyHunters, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-09-27Flink refuses a corporate ransom after an Order Hub breach, so extortion actor "LPG Group" pivots to crowdfund-style individual extortion of at least 10,000 customers and employees
- 2026-09-24ShinyHunters claims a breach of the FBI's own recruitment infrastructure via an unconfirmed Oracle PeopleSoft zero-day; the FBI now confirms the compromise itself while still investigating scope
- 2026-09-20Oracle's September 2026 Critical Security Patch Update carries fifty unauthenticated CVSS 9.8+ flaws, concentrated in Fusion Middleware's identity, forms, directory and portal components, plus E-Business Suite, Hyperion, Analytics, Enterprise Manager, Communications and Supply Chain products
- 2026-08-28Troy Hunt: a 24.9M-address ShinyHunters/Carhartt breach-claim collapses to 12.9M real records once TPC-DS synthetic benchmark data and several duplicate/test-account patterns are filtered out, a reusable methodology for verifying inflated breach-claim record counts
- 2026-07-19Ernst & Young discloses a breach of a third-party IT support-ticket platform used by its tax practice, exposing client tax and financial documents
- 2026-07-18Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records
- 2026-07-16CVE-2026-46817, Oracle E-Business Suite (Payments): unauthenticated RCE now CISA KEV-listed after quiet in-the-wild exploitation (CVSS 9.8)
- 2026-07-14Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers, none exploiting a Salesforce vulnerability
- 2026-07-10ShinyHunters' Odido (NL telecom) breach: Dutch police voice analysis points to Dutch-national involvement; same vishing-into-spoofed-portal playbook, now against an EU telco
- 2026-07-10'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration
- 2026-07-03Medtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach, 2.5 months after containment
- 2026-07-01Oracle E-Business Suite CVE-2026-46817: pre-auth RCE in the Payments File Transmission servlet, first in-the-wild exploitation
- 2026-06-28NAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pause
- 2026-06-27UK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach, 160 universities, ShinyHunters extortion, ransom paid
- 2026-06-26ShinyHunters used a single vishing call into the company's identity platform to breach Madison Square Garden
- 2026-06-21Amazon's One Medical confirms a legacy-storage breach; ShinyHunters' 8.8TB claim is unverified and its deadline expires today
- 2026-06-20Kodak confirms breach after ShinyHunters leak-site listing; June 18 deadline passed without publication
- 2026-06-13CVE-2026-48558, SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician session
- 2026-06-12CVE-2026-25089, Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)
- 2026-06-11ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration
- 2026-05-29Carnival Corporation confirms 5.99 M-record ShinyHunters breach, passport + driver's-licence numbers exposed across four cruise brands
- 2026-05-27ShinyHunters Salesforce campaign; Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affected
- 2026-05-19Grafana Labs CoinbaseCartel breach; victim confirms source-code-only theft, no customer data, ransom rejected
- 2026-05-197-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records, same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic
- 2026-05-16GTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrand
- 2026-05-09Inditex (Zara), ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromise
- 2026-05-08Instructure/Canvas extortion: 330 institutions across six countries; May 12 extortion deadline; 44 Dutch institutions confirmed
Hunting pivots
CVEs (exploited first)
Affected products
ATT&CK techniques (29 across 12 tactics)
29 techniques observed across 15 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ReconnaissancePhishing for Information: Spearphishing Voice
- Initial AccessValid Accounts · Valid Accounts: Default Accounts · Valid Accounts: Cloud Accounts · Exploit Public-Facing Application · Supply Chain Compromise: Compromise Software Supply Chain · Trusted Relationship · Phishing · Phishing: Spearphishing Voice
- PersistenceValid Accounts · Valid Accounts: Default Accounts · Valid Accounts: Cloud Accounts · Account Manipulation: Device Registration · Server Software Component: Web Shell · Modify Authentication Process · Modify Authentication Process: Multi-Factor Authentication
- Privilege EscalationValid Accounts · Valid Accounts: Default Accounts · Valid Accounts: Cloud Accounts · Account Manipulation: Device Registration
- StealthObfuscated Files or Information: Software Packing · Valid Accounts · Valid Accounts: Default Accounts · Valid Accounts: Cloud Accounts · Social Engineering: Impersonation
- Defense ImpairmentSubvert Trust Controls: Code Signing · Modify Authentication Process · Modify Authentication Process: Multi-Factor Authentication
- Credential AccessSteal Application Access Token · Unsecured Credentials: Private Keys · Modify Authentication Process · Modify Authentication Process: Multi-Factor Authentication · Adversary-in-the-Middle
- Lateral MovementRemote Services: SSH
- CollectionData from Information Repositories · Data from Information Repositories: Sharepoint · Data from Information Repositories: Code Repositories · Data from Cloud Storage · Adversary-in-the-Middle
- Command and ControlRemote Access Tools · Protocol Tunneling
- ExfiltrationExfiltration Over Web Service · Exfiltration Over Web Service: Exfiltration to Cloud Storage
- ImpactDefacement: External Defacement
Reconnaissance TA0043
T1598.004Phishing for Information: Spearphishing Voice×1
Adversaries may use voice communications to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Spearphishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.
Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗
Initial Access TA0001
T1078Valid Accounts×3
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×4
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗
T1190Exploit Public-Facing Application×5
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-09-24/shinyhunters-fbi-peoplesoft-breach-claim · 2026-07-01/oracle-e-business-suite-cve-2026-46817-pre-auth-rce-in-the-p · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗
T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.
Evidence: 2026-05-19/grafana-labs-coinbasecartel-breach-victim-confirms-source-co · ATT&CK page ↗
T1199Trusted Relationship×2
Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.
Evidence: 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · ATT&CK page ↗
T1566Phishing×1
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗
T1566.004Phishing: Spearphishing Voice×6
Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.
Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×3
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×4
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗
T1098.005Account Manipulation: Device Registration×1
Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.
Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗
T1556Modify Authentication Process×1
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.
Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×2
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · ATT&CK page ↗
Privilege Escalation TA0004
T1078Valid Accounts×3
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×4
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗
T1098.005Account Manipulation: Device Registration×1
Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.
Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗
Stealth TA0005
T1027.002Obfuscated Files or Information: Software Packing×1
Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code.
Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗
T1078Valid Accounts×3
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×4
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · 2026-06-13/cve-2026-48558-simplehelp-rmm-unauthenticated-oidc-authentic · 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗
T1684.001Social Engineering: Impersonation×1
Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims.
Evidence: 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · ATT&CK page ↗
Defense Impairment TA0112
T1553.002Subvert Trust Controls: Code Signing×1
Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature.
Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗
T1556Modify Authentication Process×1
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.
Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×2
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · ATT&CK page ↗
Credential Access TA0006
T1528Steal Application Access Token×3
Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
Evidence: 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗
T1552.004Unsecured Credentials: Private Keys×1
Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc.
Evidence: 2026-05-19/grafana-labs-coinbasecartel-breach-victim-confirms-source-co · ATT&CK page ↗
T1556Modify Authentication Process×1
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.
Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×2
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i · ATT&CK page ↗
T1557Adversary-in-the-Middle×1
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗
Lateral Movement TA0008
T1021.004Remote Services: SSH×1
Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.
Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗
Collection TA0009
T1213Data from Information Repositories×3
Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).
Evidence: 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗
T1213.002Data from Information Repositories: Sharepoint×2
Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint:
Evidence: 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗
T1213.003Data from Information Repositories: Code Repositories×1
Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.
Evidence: 2026-05-29/carnival-corporation-confirms-5-99-m-record-shinyhunters-bre · ATT&CK page ↗
T1530Data from Cloud Storage×4
Adversaries may access data from cloud storage.
Evidence: 2026-09-24/shinyhunters-fbi-peoplesoft-breach-claim · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-05-29/carnival-corporation-confirms-5-99-m-record-shinyhunters-bre · 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗
T1557Adversary-in-the-Middle×1
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗
Command and Control TA0011
T1219Remote Access Tools×1
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗
T1572Protocol Tunneling×1
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.
Evidence: 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · ATT&CK page ↗
Exfiltration TA0010
T1567Exfiltration Over Web Service×4
Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.
Evidence: 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · 2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu · 2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access · 2026-05-19/grafana-labs-coinbasecartel-breach-victim-confirms-source-co · ATT&CK page ↗
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.
Evidence: 2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce · ATT&CK page ↗
Impact TA0040
T1491.002Defacement: External Defacement×1
An adversary may deface systems external to an organization in an attempt to deliver messaging, intimidate, or otherwise mislead an organization or users. External Defacement may ultimately cause users to distrust the systems and to question/discredit the system’s integrity. Externally-facing websites are a common victim of defacement; often targeted by adversary and hacktivist groups in order to push a political message or spread propaganda. External Defacement may be used as a catalyst to trigger events, or as a response to actions taken by an organization or government. Similarly, website defacement may also be used as setup, or a precursor, for future attacks such as Drive-by Compromise.
Evidence: 2026-09-24/shinyhunters-fbi-peoplesoft-breach-claim · ATT&CK page ↗
Entries about ShinyHunters (23)
Earlier coverage (20)
Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ recordsAbbott Laboratories confirmed (2026-07-16) unauthorized access to a limited number of internal systems in its Cancer Diagnostics business (the acquired Exact Sciences unit) only. Separately, the ShinyHunters extortion group claims the intrusion began with a vishing call that compromised a Microsoft Entra ID single-sign-on account, then used it to pull 30M+ records from Entra, ServiceNow, SharePoint, Databricks and Coupa; a claim Abbott has neither confirmed nor attributed. The confirmed incident plus the same vishing-to-cloud-SSO tradecraft this actor uses against SaaS-integrated enterprises makes it relevant to healthcare and any SharePoint/Entra-dependent estate.Ernst & Young discloses a breach of a third-party IT support-ticket platform used by its tax practice, exposing client tax and financial documentsErnst & Young LLP filed breach notifications (2026-07-15) after detecting that an unauthorized party accessed a third-party IT service-management (ITSM) support-ticket platform used by its tax practice between 28 March and 12 April 2026 and downloaded documents belonging to multiple tax clients. Support tickets on the platform carried attached client tax and financial information; EY has not disclosed the access vector, the platform, or how many are affected. The transferable lesson for any organization (public-sector included) that outsources IT helpdesk/ticketing: sensitive attachments accumulate inside support-ticket systems that data-classification and DLP programs routinely overlook.Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers, none exploiting a Salesforce vulnerabilityMicrosoft Threat Intelligence documented a year (mid-2025 to mid-2026) of campaigns using ShinyHunters-associated tradecraft (registry alias UNC6240) against Salesforce-integrated SaaS environments via three intrusion paths: vishing-driven malicious-OAuth-consent (a fake Data Loader app), SaaS supply-chain OAuth-secret reuse (Salesloft Drift, Gainsight, and Storm-3138's June 2026 Klue compromise), and guest-access Aura abuse. None exploited a Salesforce flaw, all abuse trusted OAuth relationships, so sign-in-anomaly detection gives limited visibility.'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltrationReliaQuest documented a previously unreported data-extortion cluster it calls Helix, assessed as a likely continuation of the BlackFile (UNC6671) and ShinyHunters ecosystems on shared registrar and hosting infrastructure. Operators phone a target impersonating their named manager (spoofed caller-ID), walk them through an Entra ID device-code sign-in that captures a session token without a password and sidesteps Conditional Access, register a new Authenticator within minutes for persistence, then run automated SharePoint enumeration and bulk exfiltration. SharePoint + Entra ID is the default identity/collaboration stack across Swiss and EU public-sector tenants, so the playbook is directly reachable; disabling the device-code flow is the single highest-impact control.ShinyHunters' Odido (NL telecom) breach: Dutch police voice analysis points to Dutch-national involvement; same vishing-into-spoofed-portal playbook, now against an EU telcoDutch National Police announced on 9 July 2026 that its investigation into the February 2026 ShinyHunters breach of telecom operator Odido (and its Ben brand) found strong indications of Dutch-national involvement, based on forensic voice analysis of a call recorded during the intrusion. The intrusion used the ShinyHunters playbook already tracked in this store: a vishing call impersonating IT staff persuaded a customer-service employee to authenticate into a spoofed corporate portal, harvesting credentials used to bulk-export 6.2M+ customer records before the account was blocked within an hour. The new signal is the EU-telco victim, the law-enforcement attribution, and two open Dutch DPA investigations; the underlying TTP is the ShinyHunters playbook already tracked in this store.Medtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach, 2.5 months after containmentMedtronic is notifying ~9 million people of a ShinyHunters-claimed April breach of corporate IT systems (names, DOB, SSNs, health data), 2.5 months after containment; it says medical devices were unaffected and segregated from the compromised networks (BleepingComputer, 2026-07-02).Oracle E-Business Suite CVE-2026-46817: pre-auth RCE in the Payments File Transmission servlet, first in-the-wild exploitationWhat it is. CVE-2026-46817 (CVSS 9.8) is an unauthenticated remote-code-execution flaw in the File Transmission component of Oracle Payments, part of Oracle E-Business Suite, affecting EBS 12.2.3 through 12.2.15.NAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pauseNAIC (the standard-setting body for all 50 US state insurance regulators) confirms a breach via an Oracle PeopleSoft zero-day; ShinyHunters published ~3.1 TB of insurance regulatory and credit-rating-agency data, and rating-agency feeds paused, forcing NAIC to suspend assigning investment-risk designations. Part of a 100+ org PeopleSoft zero-day campaign; any organisation running Oracle PeopleSoft should verify patch status against the campaign (NAIC, 2026-06-26).UK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach, 160 universities, ShinyHunters extortion, ransom paidThe UK Cyber Monitoring Centre (CMC) published a post-incident sector review on 2026-06-25 of the April 2026 ShinyHunters (UNC6240) breach of Instructure's Canvas learning-management platform, which affected roughly 160 UK higher-education institutions (Computer Weekly, 2026-06-25).ShinyHunters used a single vishing call into the company's identity platform to breach Madison Square GardenShinyHunters breached Madison Square Garden through a single vishing call into the company's identity platform; 404 Media's review of the stolen data confirms a low-level employee was talked into letting the operators into MSG's systems, the same vishing → identity-platform (Entra/Okta) → MFA-enrollment kill chain that works equally well against EU public-sector tenants (404 Media, 2026-06-24).Amazon's One Medical confirms a legacy-storage breach; ShinyHunters' 8.8TB claim is unverified and its deadline expires todayOne Medical (Amazon) confirmed on 2026-06-13 that an unauthorised party accessed a legacy third-party file-storage system retaining archived records for One Medical Seniors (formerly Iora Health), during a 2026-06-08 to 2026-06-11 window, affecting demographic and clinical records for patients at nine clinics …Kodak confirms breach after ShinyHunters leak-site listing; June 18 deadline passed without publicationEastman Kodak acknowledged on 17 June 2026 that "an unauthorized third party illegally gained access to a limited amount of company data," after ShinyHunters listed it on their dark-web leak site on 15 June claiming 2.2 million PII records and set an 18 June contact deadline (SecurityWeek, 2026-06-18 …CVE-2026-48558, SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician sessionSimpleHelp RMM ships an unauthenticated OIDC auth-bypass (CVE-2026-48558). A forged unsigned OIDC token yields a full technician session and bypasses IdP MFA, a clean initial-access vector into every downstream MSP-managed estate (Horizon3.ai, 2026-06-12).ShinyHunters Salesforce campaign; Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affectedShinyHunters Salesforce extortion, two fresh victim confirmations. Charter Communications (Spectrum) confirmed a breach but disputes that sensitive PI or CPNI was taken (BleepingComputer, 2026-05-26), while 7-Eleven confirmed a breach affecting roughly 185,000 individuals; CyberInsider reports Social Security and driver's-licence numbers in the exposed set (CyberInsider, 2026-05-26); both trace to the vishing → Entra → Salesforce-Aura pattern.Carnival Corporation confirms 5.99 M-record ShinyHunters breach, passport + driver's-licence numbers exposed across four cruise brandsCarnival Corporation files substitute notices confirming a breach affecting 5,995,277 individuals (Maine AG filing; driver's-licence + passport numbers exposed across Princess / Holland America / Cunard / Costa per The Record). Maine AG records the breach occurring 2026-04-10 and discovered 2026-04-14 (single-employee-account social engineering); ShinyHunters claimed and ultimately published when ransom was refused.7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records, same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records (SecurityWeek, 2026-05-18). Part of the broader ShinyHunters Salesforce-targeting campaign with co-victims Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic, phishing / OAuth / misconfiguration, not Salesforce-product vulnerabilities.Grafana Labs CoinbaseCartel breach; victim confirms source-code-only theft, no customer data, ransom rejectedUPDATE (originally covered 2026-W21): Grafana Labs issued an official 2026-05-18 confirmation of the GitHub Pwn-Request breach previously reported in the 2026-W21 weekly summary (SecurityWeek, 2026-05-18; BleepingComputer, 2026-05-18; The Register, 2026-05-18).GTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrandGTIG analyses UNC6671 "BlackFile" vishing-driven AiTM extortion: real-time helpdesk impersonation → attacker-registered lookalike SSO portals → MFA token capture and rogue MFA device registration → programmatic SharePoint exfiltration of 1M+ files per victim via Python requests spoofing the Microsoft Office ClientAppId; DLS shutdown signals probable rebrand (Google Threat Intelligence Group, 2026-05-15).Instructure/Canvas extortion: 330 institutions across six countries; May 12 extortion deadline; 44 Dutch institutions confirmed(First covered 2026-05-06.) The Instructure/Canvas breach has expanded significantly in scope.Inditex (Zara), ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromiseHave I Been Pwned confirmed on 2026-05-08 that 197,400 unique email addresses from Inditex (Zara's parent, headquartered in A Coruña, Spain) were exposed following a breach of a former third-party analytics provider.
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Cl0p×2
- Medtronic breach×2
- Microsoft 365×2
- Microsoft Entra ID×2
- Microsoft SharePoint×2
- Oracle E-Business Suite×2
- Oracle E-Business Suite / Oracle Payments File Transmission unauthenticated RCE/takeover (CVSS 9.8); CISA KEV 2026-07-15, exploited ITW since 2026-06-27; fixed Oracle May 2026 CPU (12.2.3-12.2.15)×2
- Oracle PeopleSoft PeopleTools PSEMHUB pre-auth RCE (CVSS 9.8), zero-day exploited by UNC6240/ShinyHunters×2
Where this entity is cited
Source distribution
- bleepingcomputer.com22 (18%)
- securityweek.com6 (5%)
- theregister.com6 (5%)
- attack.mitre.org5 (4%)
- securityaffairs.com5 (4%)
- msrc.microsoft.com4 (3%)
- cloud.google.com3 (2%)
- cyberinsider.com3 (2%)
- other66 (55%)
All cited sources (120)
- 404media.co404 Mediahttps://www.404media.co/how-hackers-broke-into-madison-square-garden/
- 404media.co404 Media (original reporting, first to receive a data sample)https://www.404media.co/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees/
- abbott.comAbbott Laboratories (own statement)https://www.abbott.com/en-us/corpnewsroom/diagnostics-testing/abbott-statement-on-cyber-incident-in-cancer-diagnostics-business
- abnormal.aiAbnormal Securityhttps://abnormal.ai/blog/shinyhunters-sso-social-engineering-mfa-identity-compromise
- advisories.ncsc.nlNCSC-NL NCSC-2026-0189https://advisories.ncsc.nl/advisory?id=NCSC-2026-0189
- advisories.ncsc.nlNCSC-NLhttps://advisories.ncsc.nl/advisory?id=NCSC-2026-0372
- attack.mitre.orgT1190https://attack.mitre.org/techniques/T1190/
- attack.mitre.orgT1528https://attack.mitre.org/techniques/T1528/
- attack.mitre.orgT1556https://attack.mitre.org/techniques/T1556/
- attack.mitre.orgT1557https://attack.mitre.org/techniques/T1557/
- attack.mitre.orgT1566.004https://attack.mitre.org/techniques/T1566/004/
- axios.comAxioshttps://www.axios.com/2026/09/22/shinyhunters-fbi-employees-data-hack
- bankinfosecurity.comBankInfoSecurity, 2026-06-04https://www.bankinfosecurity.com/shinyhunters-leaks-234gb-dentaquest-data-trove-a-31883
- bankinfosecurity.comBankInfoSecurityhttps://www.bankinfosecurity.com/shinyhunters-threatens-to-leak-amazon-one-medical-records-a-32027
- bleepingcomputer.comBleepingComputer, 2026-05-26https://www.bleepingcomputer.com/news/security/7-eleven-data-breach-exposes-personal-information-of-185-000-people/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/
- bleepingcomputer.comBleepingComputer, 2026-05-26https://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/council-of-europe-investigates-shinyhunters-data-breach-claims/
- bleepingcomputer.comBleepingComputer, 2026-06-04https://www.bleepingcomputer.com/news/security/dentaquest-data-breach-exposed-info-of-26-million-accounts/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/grafana-says-stolen-github-token-let-hackers-steal-codebase/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/health-isac-warns-of-rising-shinyhunters-data-theft-attacks-on-healthcare/
- bleepingcomputer.comBleepingComputer, Instructure Canvas data breach, 2026-05-06https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/kodak-confirms-data-breach-claimed-by-shinyhunters-extortion-gang/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/medtronic-notifies-customers-impacted-by-shinyhunters-data-breach/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/new-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/new-oracle-e-business-suite-flaw-now-exploited-in-attacks/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/nottingham-university-data-breach-affects-over-450-000-students/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/
- bleepingcomputer.comBleepingComputer, 2026-05-08https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/
- ccb.belgium.beCCB Belgiumhttps://ccb.belgium.be/advisories/warning-fortinet-addresses-critical-command-injection-vulnerability-fortisandbox-patch
- cisa.govCISAhttps://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog
- cloud.google.comGoogle Threat Intelligence Group, 2026-05-15https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/
- cloud.google.comMandiant GTIGhttps://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft/
- cloud.google.comMandiant GTIGhttps://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/
- computerweekly.comComputer Weeklyhttps://www.computerweekly.com/news/366645159/Canvas-breach-hit-160-UK-unis-but-caused-limited-damage
- content.naic.orgNAIC security updatehttps://content.naic.org/about/security-update
- cyberinsider.comCyberInsider, 2026-05-26https://cyberinsider.com/7-eleven-data-breach-exposes-personal-information-of-185000-applicants/
- cyberinsider.comCyberInsider, 2026-05-23https://cyberinsider.com/charter-communications-confirms-data-breach-as-hackers-threaten-leak-of-42-million-records/
- cyberinsider.comCyberInsiderhttps://cyberinsider.com/ey-says-client-tax-data-exposed-in-third-party-it-software-breach/
- cyberscoop.comCyberScoophttps://cyberscoop.com/fbi-data-breach-shinyhunters-agent-safety-risk/
- cyberscoop.comCyberScoophttps://cyberscoop.com/shinyhunters-claims-fbi-attack/
- dutchnews.nlDutchNews.nl, 2026-05-08https://www.dutchnews.nl/2026/05/hackers-break-into-ed-tech-giant-again-after-massive-data-heist/
- haveibeenpwned.comHave I Been Pwnedhttps://haveibeenpwned.com/Breach/Charter
- health-isac.orgHealth-ISAChttps://health-isac.org/shiny-hunters-impact-to-health-sector-and-recommended-mitigation-strategies/
- heise.deheise onlinehttps://www.heise.de/news/Kunden-und-Mitarbeiter-von-Lieferdienst-Flink-werden-erpresst-11467086.html
- helpnetsecurity.comHelp Net Securityhttps://www.helpnetsecurity.com/2026/05/28/carnival-corporation-data-breach/
- helpnetsecurity.comHelp Net Security, 2026-06-16https://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/
- helpnetsecurity.comHelp Net Security (citing Defused)https://www.helpnetsecurity.com/2026/06/30/oracle-payments-cve-2026-46817-exploitation/
- horizon3.aiHorizon3.aihttps://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/
- infosecurity-magazine.comInfosecurity Magazinehttps://www.infosecurity-magazine.com/news/cmc-analysis-education-canvas-data/
- infosecurity-magazine.comInfosecurity Magazine, 2026-05-11https://www.infosecurity-magazine.com/news/shinyhunters-escalates-canvas/
- insidehighered.comInside Higher Ed, 2026-05-11https://www.insidehighered.com/news/tech-innovation/administrative-tech/2026/05/11/instructure-pays-ransom-canvas-hackers
- instructure.comInstructure incident pagehttps://www.instructure.com/incident_update
- insurancebusinessmag.comInsurance Business Maghttps://www.insurancebusinessmag.com/us/news/cyber/naic-confirms-peoplesoft-breach-as-cybercriminals-target-insurance-regulators-580134.aspx
- insurancejournal.comInsurance Journalhttps://www.insurancejournal.com/news/national/2026/06/25/875334.htm
- krebsonsecurity.comKrebs on Securityhttps://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/
- maine.govMaine AG breach notificationhttps://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/4fe778c0-a3a9-4dbe-8e79-2c229ac5c36b.html
- maine.govMaine Attorney General data-breach filinghttps://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/d6729ef2-7bb3-42d3-abdd-99a1dd8f2415.html
- malwarebytes.comMalwarebyteshttps://www.malwarebytes.com/blog/news/2026/06/kodak-confirms-breach-as-shinyhunters-leak-threat-reaches-deadline
- medtechdive.comMedTech Divehttps://www.medtechdive.com/news/abbott-discloses-cyberattack-on-cancer-diagnostics-business/825529/
- microsoft.comMicrosoft Threat Intelligencehttps://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/
- msrc.microsoft.comMSRChttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-26142
- msrc.microsoft.comMSRChttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45657
- msrc.microsoft.comMSRChttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-47643
- msrc.microsoft.comMSRChttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-48579
- nextgov.comNextgov/FCWhttps://www.nextgov.com/cybersecurity/2026/09/shinyhunters-says-it-wont-publish-fbi-data/416280/
- nextgov.comNextgov/FCWhttps://www.nextgov.com/cybersecurity/2026/09/stolen-fbi-data-reveals-employees-roles-intelligence-and-surveillance/416182/
- nltimes.nlNL Timeshttps://nltimes.nl/2026/09/25/individuals-sent-ransom-notes-cybercriminals-steal-flink-customer-worker-data
- nos.nlNOS (Dutch public broadcaster)https://nos.nl/artikel/2602080-hack-bij-odido-gegevens-miljoenen-klanten-in-handen-van-criminelen
- nos.nlNOS (Dutch public broadcaster)https://nos.nl/artikel/2614128-odido-ontdekte-pas-na-bericht-van-hackers-dat-klantgegevens-waren-gestolen
- nos.nlNOS (Dutch public broadcaster)https://nos.nl/artikel/2622288-bellende-odido-hacker-vermoedelijk-nederlander-politie-dreigt-stem-openbaar-te-maken
- nottingham.ac.ukUniversity of Nottinghamhttps://www.nottingham.ac.uk/currentstudents/news/student-and-alumni-data-has-been-compromised-in-a-data-security-incident
- oag.ca.govCalifornia Office of the Attorney General (breach-notification filing)https://oag.ca.gov/ecrime/databreach/reports/sb24-626542
- oracle.comOracle Security Alert CVE-2026-35273https://www.oracle.com/security-alerts/alert-cve-2026-35273.html
- oracle.comOracle (Critical Patch Update Advisory, May 2026)https://www.oracle.com/security-alerts/cspumay2026.html
- oracle.comOraclehttps://www.oracle.com/security-alerts/cspusep2026.html
- politie.nlPolitie (Dutch National Police)https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html
- prnewswire.comCarnival Corporation, Notice of Data Breachhttps://www.prnewswire.com/news-releases/carnival-corporation-notice-of-data-breach-302783524.html
- rapid7.comRapid7https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/
- reliaquest.comReliaQuesthttps://reliaquest.com/blog/threat-spotlight-helix-new-name-in-data-extortion-ecosystem
- security-hub.ncsc.admin.chNCSC-CHhttps://security-hub.ncsc.admin.ch/#/posts/12627
- securityaffairs.comSecurityAffairs, 2026-05-08https://securityaffairs.com/191859/cyber-crime/zara-data-breach-197000-customers-exposed-in-third-party-security-incident.html
- securityaffairs.comSecurity Affairshttps://securityaffairs.com/192336/data-breach/shinyhunters-hack-7-eleven-franchisee-data-and-salesforce-records-exposed.html
- securityaffairs.comSecurity Affairshttps://securityaffairs.com/192907/uncategorized/shinyhunters-leaks-charter-communications-data-potentially-impacting-5-million-customers.html
- securityaffairs.comSecurity Affairs, 2026-06-16https://securityaffairs.com/193709/ai/fortinet-warned-as-three-critical-fortisandbox-bugs-come-under-attack.html
- securityaffairs.comSecurityAffairshttps://securityaffairs.com/194463/security/attackers-actively-exploit-the-oracle-e-business-suite-flaw-cve-2026-46817.html
- securityweek.comSecurityWeekhttps://www.securityweek.com/7-eleven-data-breach-confirmed-after-shinyhunters-ransom-demand/
- securityweek.comSecurityWeekhttps://www.securityweek.com/grafana-confirms-breach-after-hackers-claim-they-stole-data/
- securityweek.comSecurityWeekhttps://www.securityweek.com/kodak-admits-data-breach-after-shinyhunters-hack-claims/
- securityweek.comSecurityWeekhttps://www.securityweek.com/nissan-employee-data-breached-in-oracle-peoplesoft-hack/
- securityweek.comSecurityWeekhttps://www.securityweek.com/oracle-addresses-peoplesoft-vulnerability-amid-reports-of-zero-day-attacks/
- securityweek.comSecurityWeekhttps://www.securityweek.com/shinyhunters-claims-council-of-europe-hack/
- simple-help.comSimpleHelphttps://simple-help.com/security/simplehelp-security-update-2026-05
- surf.nlSURF Security Advisory, Canvas Extortion Updatehttps://www.surf.nl/actualiteiten/2026/canvas-security-update
- techcrunch.comTechCrunchhttps://techcrunch.com/2026/06/10/cybercriminals-claim-breach-of-oracle-peoplesoft-servers-at-100-plus-organizations/
- techcrunch.comTechCrunchhttps://techcrunch.com/2026/09/22/hacking-group-shinyhunters-claims-it-breached-the-fbi-stole-agents-and-applicants-data/
- techradar.comTechRadarhttps://www.techradar.com/pro/security/naic-confirms-data-breach-with-shinyhunters-claiming-3-1tb-of-data-stolen-in-oracle-zero-day-attack
- techzine.euTechzine EU, 2026-05-08https://www.techzine.eu/news/security/141149/dutch-university-disconnects-canvas-systems-after-instructure-hack/
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/05/grafana-github-token-breach-led-to.html
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/07/microsoft-maps-year-long-shinyhunters.html
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html
- thenextweb.comThe Next Webhttps://thenextweb.com/news/shinyhunters-madison-square-garden-45gb-data-leak-facial-recognition
- therecord.mediaThe Recordhttps://therecord.media/cruise-giant-carnival-confirms-data-breach-affecting-6-million
- therecord.mediaThe Record, 2026-05-12https://therecord.media/instructure-pays-ransom-canvas-incident-congress-investigation
- therecord.mediaThe Recordhttps://therecord.media/university-of-nottingham-cyber-incident-shiny-hunters
- theregister.comThe Register, 2026-05-12https://www.theregister.com/cyber-crime/2026/05/12/congress-investigates-canvas-breach-after-instructure-cuts-deal-with-shinyhunters/5238927
- theregister.comThe Registerhttps://www.theregister.com/cyber-crime/2026/05/18/grafana-labs-admits-attackers-downloaded-its-codebase-from-github/5241686
- theregister.comThe Registerhttps://www.theregister.com/cyber-crime/2026/05/28/carnival-shinyhunters-cruised-off-with-6m-customer-records/5247808
- theregister.comThe Registerhttps://www.theregister.com/cyber-crime/2026/06/15/council-of-europe-hacked-in-shinyhunters-peoplesoft-heist/5255757
- theregister.comThe Register, 2026-05-12https://www.theregister.com/security/2026/05/12/double-canvas-intrusion-confirmed-as-shinyhunters-resets-leak-deadline/5238361
- theregister.comThe Registerhttps://www.theregister.com/security/2026/07/02/pacemaker-manufacturer-medtronic-warns-patients-cybercrooks-may-have-swiped-health-data/5265768
- troyhunt.comTroy Hunt (Have I Been Pwned)https://www.troyhunt.com/a-cautionary-tale-about-data-breach-claims-verification-and-carhartt/
- troyhunt.comTroy Hunt, Weekly Update 505, 2026-05-24https://www.troyhunt.com/weekly-update-505/